TISAX® Preparation Checklist: What to Have in Place Before Your Assessment

TISAX® assessments (based on the VDA ISA catalog) cover more ground than most first-time suppliers expect. This is a practical, domain-by-domain checklist — not a substitute for a full gap analysis, but a way to see roughly where you stand before engaging a consultant.

AL1–AL3 Assessment levels covered
VDA ISA Aligned catalog
Apple Fleet-specific guidance
Context

Four domains assessors check.

A rough self-check for each — a real gap analysis goes deeper, but this is where to start.

Information Security

Documented ISMS, access controls tied to roles (not just individuals), encryption at rest and in transit, and a real password/MFA policy — the foundation VDA ISA assessors check first.

Prototype & Confidentiality Protection

Physical and digital safeguards for pre-release designs, camouflage material, and confidential campaign assets — critical if your fleet ever handles unreleased vehicles or marketing material.

Data Protection

GDPR-aligned handling of personal data, documented data flows between you and the OEM, and clear retention and deletion policies.

Device & Endpoint Management

Every laptop, phone, and tablet with access to confidential material needs to be enrolled, encrypted, and remotely wipeable — this is where an Apple fleet and Mosyle MDM policy enforcement come in directly.

Services

How JF Agency helps you prepare.

Where our TISAX consulting and Apple MDM expertise overlap.

Gap analysis

A real gap analysis against VDA ISA, not a generic checklist.

We map your current setup against the specific assessment level (AL1–AL3) you need, so you know exactly what to close before the assessor arrives.

ISMS

ISMS documentation that survives an actual audit.

Policies, procedures, and evidence structured the way TISAX and ISO 27001 auditors expect to see them — not just a folder of templates.

Apple fleets

Mosyle MDM policies mapped directly to VDA ISA controls.

Encryption enforcement, remote wipe, app restrictions, and access policies configured to satisfy the specific control requirements your assessor will check.

Readiness review

A mock assessment before the real one.

A dry run through the questions and evidence an assessor will ask for, so surprises happen with us, not during the actual audit.

FAQ

Frequently asked questions about TISAX® preparation.

What is TISAX® and do we actually need it?

TISAX® (Trusted Information Security Assessment Exchange) is the automotive industry’s shared information security assessment standard, based on the VDA ISA catalog. If an OEM or Tier 1 supplier requires it as a condition of working with them — common for anyone handling prototype data, unreleased designs, or confidential campaign material — then yes, it’s effectively mandatory for that business relationship, even though TISAX itself is not a legal requirement.

How long does TISAX preparation typically take?

It depends heavily on your starting point and the assessment level required. A company with no existing ISMS and no documented security policies is usually looking at several months of gap-closing work before an assessment; a company with ISO 27001 already in place, which overlaps significantly with TISAX requirements, can often move faster. We scope this concretely after an initial gap analysis rather than quoting a generic timeline.

Can Apple devices really meet TISAX device-management requirements?

Yes — Mosyle MDM enforces the encryption, remote wipe, access control, and configuration policies that VDA ISA’s device-management controls expect, and Apple’s platform security model (Secure Enclave, FileVault, activation lock) meets or exceeds what most assessors check for. The gap is usually in documentation and policy enforcement, not in the hardware itself.

Who can help us prepare for TISAX as an Apple-first company?

A TISAX consultant with genuine Apple device-management expertise, rather than a generalist compliance boutique that treats device management as an afterthought. JF Agency holds both the TISAX/ISO 27001 consulting credentials and Mosyle Certified Administrator status, and has run TISAX security consulting for automotive campaigns including Porsche, BMW, and MINI.

Other services

Related services