Automotive businesses exchange some of the most commercially sensitive information in the supply chain. Product designs, engineering drawings, prototype information, software, manufacturing data, customer information and development plans may pass between vehicle manufacturers, Tier 1 suppliers, technology companies and specialist service providers.
Protecting this information is therefore an important part of maintaining trust within the automotive industry.
TISAX Certification and Labelling in Singapore helps automotive suppliers and service providers demonstrate that their information security practices meet the requirements expected within the automotive supply chain.
TISAX stands for Trusted Information Security Assessment Exchange and is an assessment and information-sharing scheme developed for the automotive industry.
Global Quality Services (GQS) helps Singapore organisations prepare for TISAX assessment by reviewing existing information security practices, identifying gaps, preparing evidence and supporting the organisation through the assessment and label exchange process.
What Is TISAX certification?
TISAX is designed specifically for information security in the automotive supply chain. Rather than requiring every automotive customer to conduct a separate security assessment of its suppliers, TISAX provides a common assessment and exchange mechanism.
A successful assessment produces a TISAX assessment result and applicable TISAX labels, which can then be shared with business partners through the TISAX Exchange.
This is different from ISO 27001 certification. ISO 27001 is an international management-system standard for information security, while TISAX uses the VDA ISA assessment framework and adds automotive-specific assessment objectives. An organisation may already have an ISO 27001-certified ISMS and still need a TISAX assessment when an automotive customer requires it.
For Singapore companies, this distinction is important when planning compliance. TISAX should be approached according to the requirements of the automotive customer, the information being handled and the assessment objectives applicable to the organisation.
Who Needs TISAX Certification in Singapore?
TISAX may be relevant to organisations that receive, process, store or exchange sensitive information as part of automotive projects.
This can include:
- Automotive component manufacturers and suppliers
- Engineering and design companies
- Automotive software and technology providers
- IT and cloud service providers supporting automotive customers
- Research and development organisations
- Prototype development and testing companies
- Logistics and specialist service providers
- Marketing and communications agencies handling confidential automotive information
- Suppliers working with vehicle manufacturers or Tier 1 automotive companies
The requirement is generally driven by the expectations of the automotive customer rather than by Singapore law. A supplier should therefore confirm exactly which assessment objectives and protection requirements its customer expects before registering for an assessment.
Understanding TISAX Certification Assessment Objectives
One of the most important parts of TISAX preparation is selecting the right assessment objective.
TISAX does not apply one identical checklist to every organisation. The applicable requirements depend on what type of information or assets the organisation handles.
Assessment objectives can relate to areas such as:
Information Security
This covers protection of information used in automotive business processes. Organisations need appropriate controls for areas such as access management, asset management, information security processes, supplier relationships, incident management and technical security.
Prototype Protection
Companies working with unreleased vehicles, components, designs or other prototype information may have additional physical and information-security requirements. Protection may extend to restricted areas, visitor management, surveillance, storage and handling of prototype-related information.
Data Protection
Where automotive projects involve personal data, privacy-related requirements may become relevant. Organisations should understand how personal information is collected, processed, stored, transferred and protected.
Availability and Business Continuity
Some automotive operations depend heavily on the continued availability of information and systems. Organisations may therefore need to demonstrate appropriate measures to maintain critical services and recover from disruptions. The correct assessment objectives should be established before assessment preparation begins. Choosing an unnecessarily broad scope can increase workload, while choosing an inappropriate scope can create problems later in the assessment process.
TISAX Certification and Singapore’s Data Protection Environment
TISAX does not replace Singapore’s legal requirements. Singapore organisations must continue to comply with applicable legislation, including the Personal Data Protection Act (PDPA).
The Personal Data Protection Commission states that organisations must implement reasonable security arrangements to protect personal data against unauthorised access, collection, use, disclosure or similar risks. The PDPA also includes obligations relating to accountability, retention, transfers and data breach notification.
For an automotive supplier, this becomes particularly relevant when projects involve employee information, customer information, vehicle owner data, test participants, or other personally identifiable information.
Organisations can therefore use their TISAX preparation to strengthen existing information security and privacy processes, while still treating TISAX and Singapore’s statutory obligations as separate requirements.
TISAX Certification and Cybersecurity in Singapore
Singapore has continued to strengthen its national cybersecurity environment. The Cyber Security Agency of Singapore maintains cybersecurity legislation and Codes of Practice for organisations covered by the Cybersecurity Act, while its recent cybersecurity guidance also highlights increasing risks across digital supply chains. This is particularly relevant to automotive suppliers because modern automotive projects rely heavily on interconnected IT systems, software development environments, cloud platforms and third-party technology.
For organisations that already maintain an ISO 27001 Information Security Management System, TISAX preparation can build on existing policies, risk assessments, security controls, internal audits and evidence. However, ISO 27001 alone does not automatically provide a TISAX label.
TISAX Assessment Levels
TISAX uses assessment levels to determine how an assessment is performed. The required level depends on the protection needs associated with the selected assessment objectives.
The three assessment levels are generally understood as:
- Assessment Level 1 (AL1) – a lower level of assessment where the organisation’s self-assessment is the primary mechanism.
- Assessment Level 2 (AL2) – involves additional assessment activities and plausibility checks by an approved assessment provider.
- Assessment Level 3 (AL3) – involves a more extensive assessment, including an on-site component, and is used where protection requirements are particularly high.
The required level should not be selected simply because a company wants the highest possible rating. Your automotive customer may specify the required assessment level, and the scope should be aligned with that requirement.
Our TISAX Assessment and Labelling Process

GQS takes a practical approach to TISAX preparation, beginning with the customer’s requirements rather than applying the same checklist to every organisation.
Step 1: Understand Customer Requirements
We first review what your OEM, Tier 1 customer or business partner has requested. This includes the required assessment objectives, scope, assessment level and information categories.
Starting here prevents unnecessary controls from being added to the project and helps ensure that the assessment scope reflects the actual commercial requirement.
Step 2: Define the Assessment Scope
The organisation’s locations, departments, systems, processes and information assets included in the TISAX scope are identified.
A well-defined scope is important because TISAX assessment results relate to the defined assessment scope. If important activities or locations are incorrectly excluded, this can create difficulties when sharing the result with a customer.
Step 3: Conduct an ISA-Based Gap Assessment
GQS reviews existing information security arrangements against the applicable VDA ISA requirements.
The assessment can examine areas such as:
- Information security governance
- Risk management
- Asset management
- Access control
- Supplier security
- Incident management
- Physical security
- Business continuity
- Secure development
- Network and endpoint protection
- Data protection
- Prototype protection, where applicable
The purpose is not simply to identify missing documents. We look at whether controls are actually operating and whether sufficient evidence exists to demonstrate their effectiveness.
Step 4: Prepare Policies, Controls and Evidence
Once gaps are identified, the organisation works on corrective actions. Documentation may include information security policies, risk registers, asset inventories, access records, supplier assessments, incident records, business continuity arrangements and security testing evidence. Evidence is particularly important because an organisation must be able to demonstrate that its controls are implemented in practice.
Step 5: Prepare for the Assessment
Before the formal assessment, GQS conducts a readiness review. Employees involved in the assessment are briefed on their responsibilities and the organisation’s evidence is reviewed for completeness. This stage can help prevent avoidable findings caused by inconsistent documentation, missing records or employees being unfamiliar with established security procedures.
Step 6: TISAX Assessment
The assessment is performed by an appropriate TISAX assessment provider. The assessor evaluates the organisation against the applicable requirements and assessment scope. If findings are identified, corrective actions may be required before the assessment result can be finalised.
Step 7: TISAX Label and Result Exchange
Following successful completion, the organisation receives its TISAX assessment result and applicable labels. The result can then be shared with authorised business partners through the TISAX Exchange. TISAX assessment results are generally valid for three years, after which the organisation must repeat the relevant process if it continues to require a valid TISAX result.
TISAX and ISA2027: What Singapore Companies Should Know
TISAX requirements continue to evolve. ENX has published ISA2027, which is scheduled to become the basis for TISAX assessments ordered in 2027. ENX states that assessments ordered before 1 January 2027 can still be performed using ISA 6, subject to the applicable transition arrangements. For Singapore organisations planning a new TISAX assessment, this means preparation should begin with the current customer requirement and the version applicable to the assessment order date. Companies should avoid relying on old checklists or legacy TISAX documentation without confirming which ISA version applies to their assessment.
Benefits of TISAX Assessment and Labelling in Singapore
Greater Automotive Customer Confidence
A TISAX result provides a recognised way of demonstrating the organisation’s information security status to participating automotive business partners.
Less Duplication Across Customers
Instead of responding separately to similar information security assessments from multiple automotive partners, an organisation can share its TISAX assessment result with authorised participants through the exchange mechanism.
Stronger Supply Chain Security
TISAX encourages suppliers to address information security as part of normal automotive operations rather than treating cybersecurity as an isolated IT responsibility.
Better Control Over Sensitive Information
The assessment encourages organisations to understand where confidential information is stored, who can access it, how it is transferred and how it is protected.
Improved Assessment Readiness
A structured TISAX programme can help organisations establish clearer evidence, responsibilities and security processes before customer assessments or contract reviews.
Stronger Foundation for ISO 27001
For companies considering both frameworks, TISAX preparation can complement an existing or planned ISO 27001 certification programme. The two should not be treated as identical, but an established ISMS can provide useful foundations for meeting many information-security requirements.
Why Choose GQS Singapore for TISAX Certification?
Global Quality Services helps organisations prepare for information security assessments by combining structured gap assessment with practical documentation and readiness support.
Our approach is based on understanding your actual business processes, customer expectations and information flows. We can help review your existing ISMS, identify gaps against applicable TISAX requirements, organise evidence and prepare teams for the assessment.
For organisations handling personal information, TISAX preparation can also be considered alongside ISO 27701 Privacy Information Management System certification to strengthen privacy governance.
If business continuity is an important part of your automotive operations, ISO 22301 certification in Singapore can also complement your wider resilience programme.
Frequently Asked Questions
1. Is TISAX certification mandatory in Singapore?
TISAX is not a general legal certification requirement under Singapore law. However, an automotive manufacturer or other business partner may require suppliers to obtain a TISAX assessment result as a contractual or commercial condition.
2. Is TISAX the same as ISO 27001?
No. ISO 27001 is an international information security management-system standard, while TISAX is an automotive-specific assessment and exchange scheme. An ISO 27001-certified organisation may still need TISAX if its automotive customer requires a TISAX label.
3. How long is a TISAX assessment result valid?
A TISAX assessment result is generally valid for three years. Organisations that continue to need TISAX after this period must go through the applicable reassessment process.
4. Which companies in Singapore should consider TISAX?
Automotive component suppliers, engineering companies, software providers, IT service providers, R&D organisations, prototype-related businesses and other suppliers handling confidential automotive information may need TISAX, depending on their customer requirements.
5. Can GQS perform the official TISAX assessment?
The official TISAX assessment is performed by an appropriate TISAX assessment provider. GQS can support your organisation with gap assessment, scope preparation, documentation, evidence preparation and assessment readiness so that your team is better prepared for the formal assessment.
















