tisax

Guides TISAX assessments, VDA ISA gap analysis, and ENX label preparation for automotive suppliers.

869|179|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tisax
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tisax
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tisax/skills/tisax
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tisax

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Automotive suppliers must pass TISAX assessments to win contracts with OEMs like VW, BMW, and Mercedes-Benz, but the VDA ISA catalogue, assessment levels, label selection, and ENX portal process are complex and easy to misinterpret.

Core Features & Use Cases

  • Gap Assessments: Produces structured tables mapping ISA control areas, requirement tiers, current maturity (0-5), targets, and evidence needed.
  • Label & Level Selection: Walks through assessment objectives (Confidential, Strictly Confidential, High/Very High Availability, prototype and data labels) to the correct assessment level (AL1/AL2/AL3).
  • Readiness & Audit Prep: Builds phased roadmaps to maturity 3, evidence checklists, and ISO 27001 mapping, including the ISA 6 vs ISA2027 order-date decision.
  • Use Case: A supplier asked by an OEM to obtain TISAX labels can get a complete readiness plan covering scope, audit provider selection, the 9-month corrective window, and 3-year label validity.

Quick Start

Ask the assistant to run a TISAX gap assessment for your organization against the VDA ISA 6 catalogue and recommend which labels and assessment level to pursue.

Frequently Asked Questions about tisax

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a TISAX assessment as an automotive supplier?

Register on the ENX portal, define a standard scope, select an ENX-accredited audit provider, and complete a self-assessment against the VDA ISA catalogue. Aim for consistent maturity level 3 across all applicable controls before the audit, sequencing must requirements first.

What is the difference between TISAX assessment levels AL1, AL2, and AL3?

AL1 is a self-assessment with no verification and no labels. AL2 is a remote plausibility check by an audit provider for high protection needs. AL3 is a comprehensive on-site assessment required for very high confidentiality, prototype, and Special Data objectives.

Does ISO 27001 certification replace a TISAX assessment?

No. TISAX is an assessment with shareable ENX labels, not a certification, and ISO 27001 does not substitute for it. Overlap is roughly 70-80%, but prototype protection, fixed maturity targets with cutback scoring, and OEM label requirements are TISAX-specific.

Which TISAX labels should my organization choose?

Choose objectives based on what the customer relationship touches: Confidential or Strictly Confidential for information, High or Very High Availability for services, Proto labels for physical prototypes, and Data or Special Data for GDPR processing. The objectives determine the assessment level.

When does ISA2027 become mandatory for TISAX assessments?

ISA2027 was published July 1, 2026 and is mandatory for assessments ordered from January 1, 2027. Assessments ordered in 2026 still run on VDA ISA 6, so organizations mid-readiness should choose their order date deliberately.

How long are TISAX labels valid and what happens after a failed audit?

Labels are valid for 3 years and shared via the ENX platform at your chosen disclosure level. Nonconformities trigger a corrective action plan with possible temporary labels, and follow-up assessments must complete within a 9-month corrective window.