Compliance — TISAX (Automotive)
TISAX — prototype data protection and VDA ISA monitoring for automotive suppliers
TISAX certification is required by major OEMs for suppliers handling prototype, development, and vehicle connection data. ManySignal monitors access to PDM/PLM systems, detects prototype data exfiltration, and produces VDA ISA control evidence — supporting your ENX-accredited TISAX assessment.
VDA ISA control coverage
| VDA ISA control | Requirement | ManySignal coverage |
|---|---|---|
| 1.1.1 | Information security policy | Policy compliance monitoring — detecting access that violates documented classification rules |
| 1.3.1 | Handling of information assets | Classification-based access control monitoring for confidential and highly confidential data |
| 1.3.2 | Return and disposal of information | Deprovisioning verification — confirming access removal for departing employees and contractors |
| 2.1.5 | Third-party supplier management | Supplier and contractor access monitoring — vendor credential anomaly detection |
| 3.1.2 | User access management | Privileged access monitoring and least-privilege enforcement for PLM/PDM administrators |
| 4.1.1 | Cryptographic controls | Unencrypted data transfer detection for prototype and vehicle development data |
| 5.2.5 | Information security incident management | Automated detection, triage, and case management with VDA ISA evidence export |
| 5.2.6 | Evidence collection and forensics | Tamper-evident log archive for forensic investigation of prototype data incidents |
PLM and PDM system coverage
ManySignal integrates with the PLM and PDM platforms used by automotive suppliers for prototype and vehicle development data.
PTC Windchill
Product lifecycle data access monitoring — CAD file access and download anomaly detection
Siemens Teamcenter
Engineering change order access baselining and unauthorised modification detection
Dassault ENOVIA (3DEXPERIENCE)
Multi-OEM project separation monitoring — cross-project access violation detection
Autodesk Vault
Vault administrator access monitoring and bulk checkout anomaly detection
SAP PLM
SAP authorisation object monitoring for TISAX-classified material master and document records
CATIA / NX environments
Workstation-level DLP correlation — large file transfers from engineering workstations
TISAX compliance — common questions
What is TISAX and who must comply?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment standard, developed by the German Association of the Automotive Industry (VDA) and managed by ENX. It is based on the VDA ISA (Information Security Assessment) questionnaire, which maps to ISO 27001 but adds automotive-specific requirements. OEM customers (BMW, Mercedes-Benz, Volkswagen, Stellantis, Renault) require TISAX certification from suppliers who handle prototype data, vehicle development information, or vehicle connection data.
What are the TISAX assessment objectives?
TISAX has three main assessment objectives based on the data handled: AL 2 (Assessment Level 2 — normal protection needs, e.g., confidential supplier data), AL 3 (high protection needs, e.g., prototype vehicle data and pre-production vehicle images), and AL 3 with Prototype Protection (physical and information security for prototype vehicles). ManySignal's UEBA and access monitoring addresses VDA ISA controls across all three assessment levels.
How does ManySignal address VDA ISA control 1.3 (Handling of Information Assets)?
VDA ISA control 1.3 requires classification and protection of information assets according to their sensitivity. ManySignal monitors access to data stores classified as prototype-sensitive or confidential — detecting access from accounts without documented authorisation for that classification level, bulk exports of CAD files or technical specifications, and transfers to external cloud storage inconsistent with the supplier's data handling policy.
How does ManySignal support TISAX incident detection requirements (VDA ISA 5.2.5)?
VDA ISA 5.2.5 requires information security incident detection and management capabilities. ManySignal provides: anomalous access to PDM/PLM systems (PTC Windchill, Siemens Teamcenter, Dassault Systèmes ENOVIA), exfiltration detection from engineering workstations, and credential compromise detection for accounts with access to prototype or vehicle data — with evidence formatted for TISAX assessment.
Does a TISAX assessment require an on-site audit of ManySignal?
TISAX assessments are conducted by ENX-accredited audit providers — not by VDA or OEM customers directly. The assessor reviews controls implementation across the VDA ISA questionnaire. ManySignal produces a control evidence package that maps monitoring capabilities to VDA ISA controls — supporting the supplier's assessor review without requiring ManySignal to independently undergo TISAX assessment.
Prepare your TISAX assessment evidence
Connect your Windchill, Teamcenter, or ENOVIA environment. We'll map access monitoring to your VDA ISA controls and produce assessment-ready evidence for your ENX-accredited auditor.