About TISAX
Automotive and mobility organisations increasingly require suppliers to demonstrate that they can protect confidential information, manage access, handle data responsibly, and maintain reliable information-security practices. For many vendors, TISAX becomes visible when a customer, tender, partnership, or procurement process asks for assessment results or evidence that security expectations are being met.
TISAX is not just a document request. It requires security practices, responsibilities, controls, evidence, and ways of working that can stand up to assessment and customer scrutiny. The challenge for growing suppliers is to meet those expectations without copying enterprise bureaucracy that does not fit their business.
Boxfish Labs helps organisations translate automotive security expectations into a proportionate roadmap. We assess your current maturity, identify the most important gaps, strengthen the relevant governance and controls, and prepare the documentation and evidence you need for a more confident TISAX journey.
Who this is for
- Software, SaaS, cloud, data, cybersecurity, engineering, and technology suppliers serving automotive or mobility customers
- Startups and scaleups entering automotive, mobility, connected-vehicle, fleet, logistics, or manufacturing supply chains
- SMEs responding to a TISAX request, customer audit, tender, or enterprise procurement process
- Suppliers handling confidential customer information, vehicle-related data, personal data, prototypes, development information, or sensitive operational information
- Organisations that already have some security practices but need a clearer, assessable structure
- Leadership teams that need an achievable route to stronger security without hiring a full-time CISO too early
What TISAX readiness means in practice
TISAX assessment expectations are based on the information-security requirements used in the automotive ecosystem. The exact scope and assessment objectives depend on your relationship with customers and the type of information, services, locations, and activities involved.
In practice, preparation often includes:
- Defining the relevant assessment scope, locations, systems, information, and service boundaries
- Clarifying leadership responsibilities, security ownership, policies, and risk-management practices
- Protecting confidential information, development information, prototypes, personal data, and customer assets appropriately
- Managing identity, access, devices, networks, cloud services, physical security, and secure working practices
- Assessing suppliers and subprocessors that affect security or customer information
- Establishing incident reporting, response, business continuity, and evidence-management routines
- Training employees and contractors on their security responsibilities
- Preparing documentation, evidence, and internal checks before the assessment
The goal is not to imitate a large automotive manufacturer. It is to show that your organisation understands the risks in its role and has appropriate, repeatable controls in place.
Challenges we help solve
A customer has asked for TISAX and you do not know where to begin
We help interpret the request, clarify likely scope and priorities, assess the current state, and turn the work into a practical roadmap.
We help establish the governance, policies, procedures, control ownership, risk approach, and evidence needed to demonstrate that security is managed systematically.
We help strengthen the handling of confidential information, customer data, development assets, prototypes, restricted systems, personal data, and information shared across suppliers.
Your cloud and supplier dependencies are unclear
We map key service providers, subcontractors, hosting locations, access arrangements, data flows, contracts, and dependencies that may affect your assessment and customer confidence.
Employees need to understand their role
We design practical awareness, onboarding, role-specific guidance, simulations, and reinforcement that make security expectations usable for people working with customer information and systems.
You need more than a one-off audit-preparation project
An External CISO can provide sustained leadership, risk oversight, policy governance, reporting, and continuous improvement as customer demands and the business evolve.
A practical TISAX readiness roadmap
01 - Clarify the customer requirement and scope
Understand what the customer or partner requires, the relevant assessment objectives, locations, systems, products, information types, suppliers, and timeline. A clear scope avoids both unnecessary work and damaging omissions.
02 - Assess current maturity and gaps
Review governance, policies, risk management, information handling, access, infrastructure, suppliers, physical and operational security, incident management, awareness, documentation, and existing evidence.
03 - Prioritise the most material improvements
Create a staged plan focused on the gaps that most affect assessment readiness, customer expectations, sensitive information, and operational risk. Assign owners, resources, dependencies, and realistic deadlines.
04 - Implement controls and build evidence
Put the required policies, controls, procedures, training, supplier arrangements, technical safeguards, evidence, and review routines into practice. Documentation should support real work -not only the assessment.
05 - Review and prepare for assessment
Conduct internal checks, resolve priority issues, collect evidence, validate responsibilities, prepare relevant teams, and make sure the organisation can explain how its controls work in practice.
Key readiness areas
Governance and security ownership
Defined roles, leadership support, policies, decisions, escalation paths, and accountability for information security across the organisation.
Risk management
A repeatable way to identify, assess, treat, document, accept, and review risks associated with information, systems, people, suppliers, and operations.
Practical controls for classifying, storing, sharing, accessing, retaining, and disposing of confidential customer information, development materials, prototypes, and other sensitive assets.
Identity, access, and secure working
Appropriate identity management, access control, remote-work practices, device security, authentication, onboarding, offboarding, and protection against unauthorised access.
Supplier and cloud assurance
Visibility of critical suppliers and subprocessors, security expectations in contracts, appropriate due diligence, review routines, and awareness of dependencies that affect customer information.
Incident management and continuity
Clear procedures for reporting, responding to, communicating about, recovering from, and learning from security incidents or disruptive events.
Awareness and competence
Role-appropriate training and reinforcement so people understand how to protect customer information, recognise threats, handle incidents, and work securely.
Documentation and evidence
Policies, procedures, records, approvals, risk decisions, training records, supplier reviews, technical evidence, internal checks, and other materials that demonstrate the controls are operating.
Outcomes
- A clearer understanding of the TISAX-related requirements and scope relevant to your customer relationships
- A practical readiness roadmap aligned with your business, systems, data, people, and assessment timeline
- Stronger governance, security ownership, risk management, and evidence
- Better protection of confidential information, customer assets, development information, and personal data
- More reliable supplier, cloud, access, incident, and continuity practices
- Increased confidence when responding to automotive customer requirements, tenders, due diligence, and assessments
- A security programme that remains useful after the assessment and can support wider frameworks such as ISO 27001, GDPR, DORA, or CRA