
TISAX Training
Master every phase of TISAX compliance, from understanding VDA ISA controls to managing audits and supplier security programs. This course gives automotive supply chain professionals the practical knowledge to achieve and maintain TISAX labels with confidence. Stop guessing what auditors want — learn exactly how to prepare, execute, and sustain compliance.
What your team will master:
This course covers the complete TISAX compliance lifecycle for automotive suppliers. You will learn how TISAX labels work, how to define your assessment scope, and how to navigate the VDA ISA catalog to evaluate your controls. You will conduct gap analyses, build evidence repositories, and prepare corrective action plans. The course also addresses supplier management, ISMS development, incident response, and audit communication. By the end, you will have the skills to lead your organization through a TISAX assessment and maintain compliance over time.
How your team learns in practice TISAX Training
How your team practices TISAX Training
Professionals from these companies study at Dedika









Course content
8 Chapters • 34 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to TISAX and Automotive Security
Introduction to TISAX and Automotive Security
Lesson 1 • Origins and Purpose of TISAX
Covers the history of TISAX, its creation by the automotive industry association, and the business problem it solves. Connects industry context to the need for a unified assessment standard.
Lesson 2 • TISAX Labels and Assessment Objectives
Introduces the three main TISAX label categories and their scope. Learners map label types to specific business scenarios and data sensitivity levels.
Lesson 3 • TISAX vs. Other Security Standards
Compares TISAX to ISO/IEC 27001 and other frameworks to clarify overlaps and unique requirements. Helps learners avoid redundant compliance efforts.
Lesson 4 • TISAX Ecosystem and Key Stakeholders
Identifies OEMs, suppliers, audit providers, and the ENX Association as core actors. Explains how each stakeholder interacts within the TISAX trust network.
Chapter 2HideHide detailsSee detailsTISAX Assessment Levels and Scope Definition
TISAX Assessment Levels and Scope Definition
Lesson 1 • Registering an Assessment in the TISAX Portal
Walks through the ENX TISAX portal registration process step by step. Learners complete a simulated registration to build practical familiarity.
Lesson 2 • Protection Needs and Data Classification
Introduces protection need categories and how they drive label selection. Learners apply classification criteria to real data types handled by their organization.
Lesson 3 • Understanding the Three Assessment Levels
Details AL1, AL2, and AL3 requirements, triggers, and audit depth. Learners distinguish when each level applies based on data sensitivity and OEM requirements.
Lesson 4 • Defining the Assessment Scope
Teaches how to identify in-scope locations, systems, and processes. Accurate scoping prevents audit gaps and unnecessary cost overruns.
Chapter 3HideHide detailsSee detailsISA Controls and the VDA ISA Catalog
ISA Controls and the VDA ISA Catalog
Lesson 1 • Core Information Security Controls
Covers mandatory controls in asset management, access control, and incident response. Learners assess current organizational practices against each control.
Lesson 2 • Prototype and Physical Security Controls
Addresses controls specific to prototype protection, including physical access and media handling. Learners identify gaps in physical security relevant to the prototype label.
Lesson 3 • Data Protection Controls in the ISA
Examines controls tied to personal data processing within the TISAX data protection label. Learners connect data protection obligations to specific ISA control items.
Lesson 4 • Maturity Levels and Scoring Logic
Explains the five-level maturity model used to score each control. Learners calculate maturity scores and identify the minimum level required for each assessment objective.
Lesson 5 • Structure of the VDA ISA Catalog
Explains the catalog's chapter hierarchy, control numbering, and maturity indicators. Learners navigate the catalog efficiently to locate relevant controls.
Chapter 4HideHide detailsSee detailsGap Analysis and Readiness Assessment
Gap Analysis and Readiness Assessment
Lesson 1 • Readiness Review and Internal Audit
Guides learners through a mock internal audit to validate readiness before the formal assessment. Findings feed directly into final remediation actions.
Lesson 2 • Conducting a Pre-Audit Gap Analysis
Teaches a structured method for comparing current controls to ISA requirements. Learners use a gap analysis template to document findings systematically.
Lesson 3 • Evidence Collection and Documentation
Explains what constitutes valid evidence for each control type. Learners build an evidence repository structured to support auditor review.
Lesson 4 • Prioritizing Remediation Efforts
Introduces risk-based prioritization to focus resources on critical gaps first. Learners rank findings by impact on audit outcome and business risk.
Chapter 5HideHide detailsSee detailsThe TISAX Audit Process in Practice
The TISAX Audit Process in Practice
Lesson 1 • Handling Findings and Corrective Actions
Teaches how to interpret audit findings, classify deviations, and submit corrective action plans. Learners draft a corrective action response for sample findings.
Lesson 2 • On-Site Audit Execution
Explains what auditors examine during on-site visits, including interviews, walkthroughs, and evidence review. Learners practice responding to auditor questions accurately.
Lesson 3 • The Assessment Kick-Off and Planning Phase
Details the kick-off meeting agenda, document submission requirements, and audit schedule. Learners prepare a complete audit package for the opening meeting.
Lesson 4 • Result Publication and Label Sharing
Explains how TISAX results are published in the ENX portal and shared with requesting OEMs. Learners configure sharing permissions and understand result validity periods.
Lesson 5 • Selecting and Engaging an Audit Provider
Covers criteria for choosing an ENX-accredited audit provider and structuring the engagement. Learners draft a request for proposal and evaluate provider responses.
Chapter 6HideHide detailsSee detailsInformation Security Management System for TISAX
Information Security Management System for TISAX
Lesson 1 • Policy and Procedure Development
Covers the minimum policy set required by the ISA and how to write enforceable procedures. Learners draft a sample policy using a TISAX-aligned template.
Lesson 2 • Continuous Monitoring and Improvement
Introduces KPIs, internal audits, and management reviews to sustain ISMS effectiveness. Learners design a monitoring calendar that supports TISAX renewal cycles.
Lesson 3 • Risk Assessment and Treatment
Applies a structured risk assessment process to identify and treat information security risks. Learners produce a risk register aligned to TISAX control domains.
Lesson 4 • ISMS Foundations Aligned to TISAX
Establishes the core ISMS elements required by the ISA catalog. Learners map ISMS components to specific ISA control clusters.
Chapter 7HideHide detailsSee detailsSupplier and Third-Party TISAX Management
Supplier and Third-Party TISAX Management
Lesson 1 • Mapping the Supplier Security Landscape
Teaches how to identify which suppliers handle in-scope data and what obligations apply. Learners build a supplier inventory with associated TISAX relevance ratings.
Lesson 2 • Supplier Assessment and Monitoring
Explains how to assess supplier security posture through questionnaires, audits, and TISAX result verification. Learners design a supplier assessment workflow.
Lesson 3 • Managing Subcontractor Chains
Addresses the complexity of multi-tier subcontracting and how to maintain visibility of security controls. Learners apply flow-down requirements to a sample supply chain scenario.
Lesson 4 • Contractual Security Requirements
Covers the security clauses that must appear in supplier contracts to satisfy ISA controls. Learners review and annotate a sample supplier agreement.
Chapter 8HideHide detailsSee detailsSustaining TISAX Compliance and Strategic Maturity
Sustaining TISAX Compliance and Strategic Maturity
Lesson 1 • Advancing Maturity Beyond Minimum Thresholds
Guides organizations from minimum compliance to higher maturity levels for competitive advantage. Learners identify maturity improvement opportunities across control domains.
Lesson 2 • Lessons Learned and Continuous Improvement
Establishes a lessons-learned process to capture audit insights and prevent recurring findings. Learners design a post-audit review template for organizational learning.
Lesson 3 • Integrating TISAX into Business Strategy
Shows how TISAX compliance can be positioned as a market differentiator and OEM relationship enabler. Learners develop a business case for sustained TISAX investment.
Lesson 4 • TISAX Renewal and Reassessment Planning
Explains renewal timelines, triggers for reassessment, and how to manage scope changes. Learners create a renewal calendar integrated with the ISMS review cycle.
Your valid completion certificate
This course is for you:
Information security manager: responsible for achieving a first TISAX label quickly.
Compliance officer: expanding their portfolio into automotive supplier security requirements.
IT manager at a Tier-1 supplier: facing OEM pressure to demonstrate formal security compliance.
Quality or risk manager: tasked with integrating TISAX into existing assurance programs.
Security consultant: advising automotive clients who need structured TISAX guidance.
Career changer from general IT: moving into automotive cybersecurity and compliance roles.
Related Courses
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course



















