TISAX Readiness Consulting for Automotive Suppliers
Assessment Level 2 and 3 readiness, prepared against the ISA2027 catalogue and integrated with your ISO 27001 and NIS 2 obligations, so the ENX-approved provider you choose finds a mature system.
Readiness from $12,000 per location. We prepare you; the approved provider assesses you. We will never blur that line.

Why Suppliers Come to Us for TISAX
An OEM purchasing contract now requires a TISAX label
BMW, the VW Group, Mercedes-Benz, Audi and their Tier 1 suppliers push TISAX down the chain as a purchasing gate. Without a label at the right assessment level for the right location, the sourcing conversation stops. More than 20,000 sites across 90 countries have already been assessed.
ISA2027 changes the catalogue you are being assessed against
The ENX Association published ISA2027 in July 2026 and it becomes mandatory for every assessment ordered from 1 January 2027, with an annual catalogue cycle after that. Preparing against the retiring VDA ISA 6 catalogue is the most expensive mistake available this year.
Your ISO 27001 certificate does not get you the label
TISAX shares most of its control logic with ISO 27001, and roughly 80 percent of the effort overlaps if you have a working ISMS. But the assessment is separate, per location, at a defined level, by an ENX-approved provider. A certificate is a head start, not a substitute.


Assessment Levels, Modules and Scope
Your customer defines the protection needs, the protection needs define the level, and the level defines how deep the assessment goes and whether it comes on site. Getting the target wrong at scoping is the second most expensive mistake after preparing against the wrong catalogue.



What We Do, and What Only an Approved Provider Can Do
We run the gap analysis, align the work with your ISMS, remediate with your team, build the evidence file and run a mock assessment. That is readiness, and it is where labels are won or lost.
The assessment itself is performed, and the label issued, only by the audit providers approved by ENX. There are seventeen of them. We are not one, we are independent of all of them, and we will help you choose.
We put this on the first screen because the consultancies that blur it are the ones whose clients discover the difference on assessment day.
Who Needs a TISAX Label?

Compared With Typical TISAX Consultancies
| Atlant Security | Typical consultancy | |
|---|---|---|
| Honesty about the label | We prepare you. Only the ENX-approved audit providers assess and issue labels, and we say so on page one | Pass guarantees and blurred lines about who issues what |
| Physical and OT controls | AL3 physical security, prototype areas and plant networks assessed by someone with critical-infrastructure fieldwork behind them | Office IT consultants who have never walked a plant |
| NIS 2 overlap | One programme designed to satisfy TISAX and the NIS 2 risk-management requirements together | Two parallel projects, two evidence files |
| Catalogue | Prepared against ISA2027 from the start | Still selling VDA ISA 6 readiness |
| Pricing | Published, fixed, per location | Quote after the free consultation |
Readiness in Four Phases
Scoping
Locations in scope, protection needs from your OEM requirements, target assessment level, and which additional modules apply. Registration on the ENX portal if you are not yet a participant.
Gap analysis
Every VDA ISA control assessed against your current state, mapped to your ISO 27001 ISMS where you have one so nothing is built twice. Physical security and prototype handling assessed on site where AL3 applies.
Remediation
Policies, technical hardening, physical controls, supplier management and the evidence file, in the order the assessment will examine them. Your team does the work with us, so the maturity is real.
Mock assessment and hand-off
A dry run against the target level, then hand-off to the ENX-approved audit provider you choose. We support you during the assessment and through any corrective action plan.

TISAX Readiness Pricing
Published and fixed per location. The approved provider charges its assessment fee separately; we tell you what to expect there too, because nobody else does.
Assessment Level 2 Readiness
Normal protection needs, one location, remote assessment by the provider.
- Scoping and ENX portal registration support
- Gap analysis against ISA2027, mapped to your ISMS
- Remediation plan and evidence file
- Policy and technical control build with your team
- Mock assessment before hand-off
Assessment Level 3 Readiness
High and very high protection needs, on-site assessment, physical and prototype controls.
- Everything in AL2 readiness
- On-site physical security and prototype area assessment
- Plant and OT network segmentation review
- Prototype and data protection modules
- On-site mock assessment
- Support during the assessment and corrective action plan
Multi-location groups are priced per site in writing before we start. You review each deliverable before you pay.
Prepare Against ISA2027, Not the Catalogue Being Retired
One scoping call to confirm level, modules and locations from your actual OEM requirements, then a fixed-price plan in writing.
Book Your TISAX Scoping Call