← All Services
🚗
AUTO

Winners provides TISAX × ISO 21434 automotive cybersecurity certification for OEMs and Tier 1/2 suppliers — VDA ISA assessment, gap analysis, and mock audits.

TISAXISO 21434ISO 26262UN R155IATF 16949

TISAX × ISO 21434 × ISO 26262 × UN R155 × IATF 16949

積穗科研股份有限公司 · Winners Consulting Services Co. Ltd.

TISAX is not an ISO certificate but the automotive industry's information security assessment and exchange mechanism: an ENX-approved audit provider assesses you against the VDA ISA catalogue, and results are shared with customers on the ENX platform as labels valid for up to three years. VDA ISA2027 was published on 2026-07-01 and applies to assessments ordered from 2027-01-01; assessments ordered before then can still use ISA6. We integrate TISAX, ISO/SAE 21434 and UN R155 to help OEMs and Tier 1/2 suppliers complete the VDA ISA self-assessment, gap analysis, security control implementation and mock audits. We are consultants, not an issuing body.

Winners provides TISAX × ISO 21434 automotive cybersecurity certification for OEMs and Tier 1/2 suppliers — VDA ISA assessment, gap analysis, and mock audits.

Intended Beneficiaries

  • ✓OEMs and Tier 1 / Tier 2 automotive component suppliers
  • ✓Automotive semiconductor, ECU, ADAS system, and V2X connectivity developers
  • ✓Taiwanese companies targeting European (VW, BMW, Mercedes) or Japanese supply chains
  • ✓Manufacturers already holding IATF 16949 certification looking to add cybersecurity and functional safety compliance

The Difference Between Acting and Waiting

🏆

✅ When you act

After passing TISAX certification, Taiwanese automotive component manufacturers are directly added to the approved supplier lists of BMW, Bosch, Continental, and other Tier 1 European manufacturers — stable annual frame orders instead of competing purely on price.

⚠️

❌ When you wait

Taiwanese suppliers without TISAX certification are filtered out at the inquiry stage by European manufacturers — no chance to even submit a quote, forced to compete on price in lower-tier Asian markets.

🌐

✅ When you act

After the EU Cyber Resilience Act (CRA) takes effect in 2027, Taiwanese connected component manufacturers that complete compliance early have their CE mark in hand and the EU market open — first movers capturing the market vacuum under the new standard.

⚠️

❌ When you wait

Manufacturers insufficiently prepared for CRA compliance face EU market export barriers after 2027, with entire shipments stopped at customs. Losses during the transition period are counted in the hundreds of millions.

📊

✅ When you act

Suppliers with ISO/SAE 21434 certification are prioritized in EV supply chain integration — OEMs know their cybersecurity management is trustworthy, enabling deeper technology collaboration and more stable orders.

⚠️

❌ When you wait

Suppliers without automotive cybersecurity certification face a hard barrier in the EV wave: no cybersecurity compliance means no supply chain access. Traditional advantages are neutralized by a single certification requirement.

Framework Comparison & Implementation Strategy

TISAX vs ISO 27001 — Which do automotive manufacturers require?

TISAX (VDA ISA)

The VDA ISA questionnaire is developed by the German Association of the Automotive Industry (VDA) and the assessment exchange is operated by the ENX Association; VDA ISA2027 applies to assessments ordered from 2027-01-01. Designed specifically for automotive supply chains. BMW, Bosch, Daimler, and other European manufacturers require suppliers to hold a TISAX label — ISO 27001 is not an accepted substitute.

ISO 27001

General information security management standard applicable to all industries. Effective for foundational security frameworks, but does not meet European automotive manufacturers' specific supply chain cybersecurity audit standards and cannot substitute for TISAX.

積穗科研:Winners provides integrated TISAX + ISO/SAE 21434 advisory — using ISO 27001 to establish the foundational framework, then extending to TISAX automotive supply chain-specific requirements. The shortest path to obtaining a TISAX label.
EU CRA Impact on Taiwan Manufacturers: 2027 deadline — what to do now?

CRA Requirements

From 2027, all products with digital elements sold in the EU market (connected devices, IoT, software) must comply with mandatory cybersecurity requirements throughout their lifecycle and obtain CE marking. Non-compliance means products banned from the EU market.

Taiwan Manufacturing Reality

Most Taiwanese connected device manufacturers have not designed their products with CRA requirements in mind. Comprehensive upgrades across product design, firmware security, and vulnerability response mechanisms are needed — the time window is closing.

積穗科研:Winners provides CRA + IEC 62443 integrated advisory — helping Taiwanese manufacturers complete product design conformity assessments, establish vulnerability management mechanisms, and obtain CE marking to ensure smooth EU market entry before 2027.

Service Delivery Process (Four Stages)

01

TISAX Scope Definition & Self-Assessment

Conduct a current-state inventory using the VDA ISA questionnaire (information security, prototype protection, data protection) and define scope and target level (AL 2 / AL 3).

02

Gap Analysis & Remediation Roadmap

Identify technical and process gaps against TISAX, ISO 21434, and ISO 26262, and develop a prioritized remediation roadmap.

03

Controls Implementation & Documentation

Establish TISAX-compliant information security controls and ISO 26262 functional safety plan (FSP), safety case, and all required documentation.

04

Audit Preparation & Certification

Support selection of an accredited audit body (ENX-recognized), conduct mock audits, address non-conformances, and provide full-engagement support through TISAX or ISO 26262 ASIL certification.

Frequently Asked Questions

How is Winners Consulting different from other consulting firms?▼

Winners Consulting Services Co., Ltd. is a hands-on, practitioner-led team. Unlike single-discipline firms, Winners integrates process optimization, legal compliance, and cybersecurity engineering in one team: engagements are executed personally by VP-level or above consultants — never outsourced — from system design and regulatory mapping through to technical implementation and certification. Winners delivers Big Four-level quality with cross-functional integration synergy that better fits real-world enterprise needs, at more competitive fees than the Big Four - built for companies that genuinely want to strengthen their corporate fitness and create new blue-lake markets.

What is the relationship between TISAX and ISO/SAE 21434?▼

TISAX is the European automotive industry's assessment mechanism for information security, based on the VDA ISA questionnaire. ISO/SAE 21434 is an international standard specifically for automotive cybersecurity engineering. They are complementary: TISAX focuses on supplier information security governance, while 21434 focuses on cybersecurity engineering throughout the product development lifecycle.

How is the ASIL level determined in ISO 26262?▼

ASIL is determined through Hazard Analysis and Risk Assessment (HARA), considering Severity (S), Exposure (E), and Controllability (C), ranging from ASIL A (lowest) to ASIL D (highest). Winners assists you in conducting HARA to correctly determine the ASIL level for each function.

Do Taiwanese suppliers entering European OEM supply chains definitely need TISAX?▼

Yes. Most European OEMs have made TISAX AL 2 or AL 3 assessment a mandatory supplier qualification requirement. Winners helps Taiwanese suppliers achieve recognition via the most efficient pathway.

How long is TISAX assessment validity?▼

TISAX assessment results are valid for 3 years. Re-assessment is required before expiry. Winners provides ongoing compliance maintenance services to ensure smooth re-assessment.

Enquire About This Service

TISAX × ISO 21434 Automotive Cybersecurity Consulting — OEM Supply Chain

Request a Complimentary Consultation

Related Deep Insights

In-depth analysis by Winners consultants, 6,000+ words per article

auto

The Autonomous Driving Trust Case: A Complete Safety Argument Framework Beyond ISO/SAE 21434 Compliance

A 2023 Norwegian study found trust and safety are statistically unrelated, revealing that an ISO/SAE 21434 cybersecurity case alone cannot build public trust in autonomous driving. The research proposes a supplementary 'Trust Case' framework to present AI transparency and organizational accountability in layperson's terms. Taiwanese suppliers must build a complete, customer-facing safety argument beyond TISAX certification and UNECE WP.29 compliance to address this critical gap.

auto

Team Structure Insights from ISO/SAE 21434 Development: The Organizational Key to Automotive Cybersecurity Compliance in Taiwan

Using the ISO/SAE 21434 development process as a case study, Zhang Hengwei's research reveals that team structure is the most critical IPO factor affecting international standard quality. For Taiwan's automotive suppliers, this means the success of TISAX certification and ISO/SAE 21434 implementation hinges on establishing a cross-functional cybersecurity governance team.

auto

Optimizing Early-Stage Automotive Cybersecurity Process Design: A Practical Analysis of ISO/SAE 21434 and TISAX Compliance

Research by Christine Jakobs (2023) reveals systemic gaps in the early design phase of the automotive cybersecurity V-Model, leading to an incomplete ISO/SAE 21434 compliance evidence chain. The study proposes a function-oriented risk analysis method to identify threats before system architecture is finalized. This approach is crucial for Taiwanese suppliers preparing for TISAX certification and complying with UNECE WP.29 UN-R155 regulations, offering a practical framework to strengthen early-stage security practices and ensure robust compliance.

auto

Proposing HEAVENS 2.0: An Automotive Risk Assessment Model – Winners Consulting Services Insights

Winners Consulting Services Co., Ltd. highlights HEAVENS 2.0 as the vehicle risk assessment model that most closely aligns with ISO/SAE 21434 requirements. The research team systematically identified 17 model updates—12 to address compliance gaps and 5 to remediate weaknesses—fully aligning the original HEAVENS framework with mandatory UN R155 regulations. This provides a clear gap analysis checklist for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 implementation.

auto

AMCSF: New Cloud Compliance Requirements for ISO 21434 and TISAX

Geol Kang's 2025 Automotive Multi-Cloud Security Framework (AMCSF) reveals that in the era of Software-Defined Vehicles, the primary attack surface has shifted from the vehicle to the cloud backend. The five-layer defense architecture integrates the ISO/SAE 21434 lifecycle and emphasizes the necessity of CSPM tools. Taiwanese OEMs and Tier-1/Tier-2 suppliers must incorporate cloud security into their TISAX assessment preparations to meet these evolving compliance demands and secure their position in the supply chain.

auto

ISO/SAE 21434 Gap Analysis: Systematically Strengthening TARA Management and Incident Handling

A 2023 arXiv paper reveals systemic gaps in ISO/SAE 21434 concerning cross-supply chain TARA management and vulnerability incident handling, proposing 13 new terms and 4 new process steps. Taiwanese automotive suppliers, during TISAX certification and UNECE WP.29 compliance, should prioritize strengthening post-production incident response and TARA lifecycle management. Winners Consulting Services offers a 90-day implementation plan to address these critical areas and ensure robust compliance.

auto

Quantifying Systemic Cybersecurity Impacts of Connected Vehicles: A Key Extension for ISO 21434 TARA

The current ISO/SAE 21434 TARA framework, limited to a single-vehicle boundary, fails to quantify the cascading impacts of connected vehicles on the entire traffic system. A new study simulates three attack scenarios, introducing for the first time systemic operational and safety impact vectors to provide an objective basis for TARA impact ratings. Taiwanese automotive suppliers pursuing TISAX certification and UNECE WP.29 compliance must incorporate this systemic risk perspective into their threat analysis to meet evolving OEM requirements and enhance the defensibility of their cybersecurity management systems.

auto

An Adaptable Security-by-Design Approach — Winners Consulting Services Insights

Winners Consulting Services Co., Ltd. highlights a 2025 study by UK scholar Jeremy Bryans et al., which is the first to systematically apply the Security-by-Design concept from ISO/SAE 21434 to the entire lifecycle of vehicle OTA updates. The research integrates Threat Analysis and Risk Assessment (TARA) with UNECE WP.29 mitigation requirements, offering a practical framework for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 compliance.

All Advisory Services