You've Registered for TISAX. Now What?

What to Do When the TISAX Self-Assessment Suddenly Feels Overwhelming

You've been told your business needs TISAX.

You've researched what it is. You've spoken internally. You've registered with ENX and started the process.

Then you get to the assessment requirements.

And suddenly TISAX feels considerably bigger than it did at the beginning.

There are questions about information security, policies, processes, responsibilities, access controls, suppliers, risk management and evidence.

Some you can answer immediately.

Some you're fairly sure your business does.

And others leave you thinking:

“Do we actually have this?”

If that's where you've reached, don't panic.

This is often the point where preparing for TISAX stops being a certification exercise and becomes a much broader review of how information security actually works within your organisation.

And identifying those gaps is part of the process.

Business reviewing the TISAX self-assessment and VDA ISA requirements

What Happens After You Register for TISAX?

Registration isn't the assessment itself.

TISAX is operated by the ENX Association. The official process moves through registration, selection of an approved audit provider, assessment and ultimately the exchange of assessment results.

During registration, your organisation defines its assessment scope and selects the relevant assessment objectives. Those objectives are particularly important because they determine the expected level of information security according to the type of information you're handling.

The assessment itself is based on the VDA Information Security Assessment (ISA).

And this is where many organisations begin to appreciate the amount of work involved.

Then You Meet the VDA ISA

The ISA is the information security requirements catalogue underpinning the TISAX assessment.

For assessments being ordered during 2026, ENX currently provides ISA 6.0.3 as the applicable questionnaire; ISA2027 has already been published for assessments ordered from 2027.

It's not simply asking whether you have antivirus installed or whether employees use strong passwords.

It's looking much more broadly at how your organisation manages information security.

And that's where that “damn” moment can happen.

You might discover that something happens within the business but isn't documented.

You may have security technology in place but no clearly defined policy supporting it.

Responsibilities might exist informally without clear ownership.

A process might depend entirely on one person knowing what to do.

Or you may encounter requirements your organisation simply hasn't considered before.

That's useful information, because now you know where the gaps are.

“But We Already Do Most of This”

This is something we hear frequently with compliance.

And you may be right.

Your business might already be doing a significant amount correctly.

The challenge is the difference between:

Doing something

and

having a defined, repeatable and demonstrable process for doing it.

Take employee departures.

Perhaps somebody tells IT when an employee leaves, their Microsoft 365 account gets disabled and their laptop gets returned.

Great.

But what's the actual process?

Who is responsible for starting it?

When should access be removed?

Which systems need checking?

What happens to company data?

What evidence demonstrates that the process was followed?

What happens if the usual person responsible is on holiday?

Suddenly a simple “Yes, we remove people's accounts” becomes a governance question.

That's the kind of thinking that makes TISAX preparation valuable beyond the assessment itself.

IT and business teams reviewing gaps identified during TISAX assessment preparation

Don't Start Creating Documents Just to Answer Questions

This is where businesses can make the process unnecessarily difficult.

You see a requirement.

You don't currently have something documented.

So you download a template, change the company name and think:

Done.

But a policy that doesn't reflect what your organisation actually does isn't particularly useful.

Instead, use the assessment to understand the underlying requirement.

What risk is it addressing?

What does your organisation currently do?

What's missing?

Does a technical control need implementing?

Does a process need improving?

Does somebody need clear responsibility?

Does that then need documenting?

Your policies, processes and technology should support each other.

Break the Assessment Into Gaps

Don't look at the entire questionnaire as one enormous project.

Turn it into a gap analysis.

For each relevant requirement, establish where you currently stand.

You might effectively end up with four categories:

Already in place and evidenced

You have the control, process and appropriate evidence.

In place but not properly documented

The business does it, but the process needs formalising.

Partially implemented

Something exists, but it doesn't fully address the requirement.

Missing

A new control, process, policy or technical change may be required.

That immediately turns an intimidating questionnaire into a project plan.

And importantly, not every gap is an IT problem.

TISAX Isn't Just an IT Project

This is one of the biggest misconceptions to avoid.

Your IT team or IT provider will certainly have an important role.

But TISAX reaches into wider organisational governance.

HR may be involved in starter, mover and leaver processes.

Leadership needs to establish responsibilities and risk ownership.

Procurement may need to consider supplier relationships.

Employees need to understand policies.

Facilities may be involved where physical security is relevant.

Your IT environment needs to support the controls the organisation says it has.

TISAX preparation therefore needs involvement from across the business rather than simply forwarding the questionnaire to whoever manages your computers.

Where Your IT Provider Becomes Important

There will inevitably be questions where you need to understand exactly what is happening technically.

For example:

How are devices managed?

How quickly are security updates deployed?

How is access controlled?

Is multi-factor authentication enforced?

How are backups managed and tested?

What security monitoring exists?

How are administrator accounts controlled?

What happens when somebody leaves?

How is information protected when employees work remotely?

Which systems are exposed to the internet?

Your answers need to reflect your real environment.

This is where Sunrise Technologies can help.

We can work with your organisation to understand the technology and security controls already in place, identify gaps and help implement improvements where required.

Automotive manufacturing business preparing its information security environment for TISAX

Don't Guess Your Way Through It

If you don't understand a question, don't simply choose the answer that sounds closest.

The assessment objective and scope you've registered matter. ENX describes the assessment scope as defining which parts of the organisation are covered, while the assessment objectives determine the expected information-security level based on the information being handled.

Those decisions also influence how the audit provider approaches the assessment.

So if something isn't clear, establish what the requirement actually means for your organisation before deciding what needs changing.

You Haven't Failed TISAX

This is probably the most important point.

Finding gaps during preparation doesn't mean you've failed.

You haven't suddenly discovered that your business is terrible at cyber security.

You've discovered where your current position differs from the position you need to reach.

And discovering that before the assessment gives you an opportunity to do something about it.

Think of the questionnaire as a map.

You now know where you are.

You know where you need to get to.

The next job is working out the route between the two.

Turn Your TISAX Questionnaire Into an Improvement Plan

Once you've identified the gaps, prioritise them.

Some may require straightforward documentation.

Some may require policy changes.

Some will require technical work.

Others could involve wider changes to responsibilities, suppliers, processes or governance.

Assign ownership.

Agree what needs to happen.

Collect evidence as improvements are implemented.

And keep everything organised.

You're no longer staring at a huge assessment wondering where to begin.

You're working through a defined improvement programme.

When Should You Choose Your Audit Provider?

Once your participant and scope registration is successfully completed, ENX provides a Registry Excerpt and contact information for approved TISAX audit providers, allowing you to request bids for the assessment.

The audit provider is separate from the organisation helping you prepare.

That's an important distinction.

The approved audit provider conducts the TISAX assessment and provides the assessment result.

Sunrise's role is different.

We help you get your environment ready.


How Sunrise Technologies Can Help When You've Already Started TISAX

Maybe you've already registered.

Maybe you've downloaded the ISA.

Maybe you've even started working through it.

And now you've realised there are questions you can't confidently answer.

That's absolutely fine.

You don't need to abandon what you've done and start again.

Sunrise Technologies can work with your business from where you are today.

We can help you understand your existing IT environment, identify technical and procedural gaps, strengthen security controls, improve policies and governance, and build a clearer plan for the work required before assessment.

Where something is already working, we don't need to reinvent it.

Where something needs improving, we can identify what needs to change.

And where the questionnaire has exposed a genuine weakness in the business, we can help you address the underlying problem rather than simply trying to find the right answer for the form.

Because ultimately, TISAX preparation isn't about making a spreadsheet look good.

It's about being able to confidently demonstrate that the controls and processes behind those answers actually exist.

Already Started TISAX and Need Help With the Next Step?

You've registered. You've opened the assessment requirements. Now you need to work out what comes next.

Talk to Sunrise Technologies about reviewing your current environment and turning the gaps you've discovered into a practical plan.


Callie Poston

I am the founder of Forever Callie Media, A Content Creation Agency in Essex England. My main focus is to make sure small independent businesses get professional marketing that makes them stand out from the crowd.

https://forevercallie.com
Next
Next

Sunrise Technologies Named Official Main Partner of Southend United for 2026/27