TISAX 評估與 VDA ISA2027
2027 年 1 月 1 日起,新委託的 TISAX 評估一律改用 ISA2027——在 2026 年底前委託,還能依熟悉的 ISA 6.0.3 完成。
Book a Free Risk DiagnosisTISAX(Trusted Information Security Assessment Exchange)是汽車產業的資訊安全評估與結果交換機制:評估問卷 VDA ISA 由德國汽車工業協會(VDA)制定,機制由 ENX 協會營運,評估須由 ENX 核准的稽核服務商執行,結果以評估標籤在 ENX 平台與車廠共享,效期最長三年。TISAX 是車廠的商業要求而非法律義務,也不是 ISO 證書——市場上習稱的「TISAX 認證」,正式說法是評估標籤。VDA 已於 2026 年 7 月發布 ISA2027,改以年份命名並逐年發布;2027 年 1 月 1 日起委託的評估一律適用。
ISA2027 改了什麼
資訊安全模組維持 46 項控制,其中 44 項經修訂:新增危機管理要求(1.6.3)、政策義務改為強制(1.1.1)、遠距工作改寫為具體的強制要求(2.1.4),供應商驗證義務加嚴(原 1.2.4 移至 6.1.3)。資料保護模組的 12 項控制與 ISA 6 相同。變動最大的是原型保護模組。
原型保護模組重構:只剩兩種標籤
原型保護由 22 項控制精簡為 20 項,原本 8.1 至 8.5 五節併為兩節:8.1 組織要求、8.2 實體與環境安全。標籤只剩 Prototype Protection Basic(AL2)與 Prototype Protection Facilities(AL3)兩種;Facilities 涵蓋 Basic 的全部要求,並要求場址具備保管原型的實體防護。評估範圍含原型保護者,即使實際措施不變,文件架構也需要重新對映。
該依 ISA 6.0.3 還是 ISA2027?
決定因素是委託日,而不是評估日:2026 年 12 月 31 日前委託的評估,仍可依 ISA 6.0.3 完成;2027 年 1 月 1 日起委託者一律適用 ISA2027。既有標籤維持原效期(最長三年),不需要提前複評。標籤將在 2027 年到期、且評估範圍含原型保護的供應商,宜盡早評估是否在今年底前委託。
TISAX、ISO 27001 與 ISO/SAE 21434 的分工
ISO 27001 是跨產業的資安管理標準;TISAX 在資安控制之外增加原型保護與資料保護模組,並透過 ENX 平台共享評估結果,避免對每家車廠重複評估。ISO/SAE 21434 則是車輛產品開發的網路安全工程標準(對應 UN R155 型式認證要求),與 TISAX 互補而非取代。
積穗科研的 TISAX 輔導流程
一、範疇界定與現況診斷:依 VDA ISA 的資訊安全、原型保護、資料保護模組盤點現況,界定評估範疇與目標等級(AL2/AL3),出具差距分析。二、整改計畫與制度建立:依優先順序建立資訊安全、供應商管理與原型保護等程序文件。三、ISO/SAE 21434/ISO 26262 整合(選配):共用安全政策框架與風險評估底稿,避免重複建置。四、模擬稽核與正式評估陪伴:協助選擇 ENX 核准的稽核服務商,完成模擬稽核與不符合項修正,陪同取得 TISAX 評估標籤。
輔導實績
車用散熱系統廠:通過 TISAX AL2 評估,列入歐系 Tier 1 合格供應商名單,進入德系車廠熱管理系統供應鏈。鋁合金精密加工廠:TISAX 與 ISO/SAE 21434 同步輔導,一次完成資訊安全管理與汽車網路安全工程的制度建置。
Who This Is For
- 接觸歐系車廠機密設計資料、原型件或個人資料的 Tier 1/2 供應商
- 被 Tier 1 客戶要求提供 TISAX 評估結果的 Tier 2/3 供應商(如散熱模組、鋁合金加工)
- 標籤將於 2027 年到期、需決定依 ISA 6.0.3 或 ISA2027 複評的企業
- 評估範圍含原型保護、需因應模組重構的供應商
Related Deep Insights
In-depth analysis by Winners consultants, 6,000+ words per article
The Autonomous Driving Trust Case: A Complete Safety Argument Framework Beyond ISO/SAE 21434 Compliance
A 2023 Norwegian study found trust and safety are statistically unrelated, revealing that an ISO/SAE 21434 cybersecurity case alone cannot build public trust in autonomous driving. The research proposes a supplementary 'Trust Case' framework to present AI transparency and organizational accountability in layperson's terms. Taiwanese suppliers must build a complete, customer-facing safety argument beyond TISAX certification and UNECE WP.29 compliance to address this critical gap.
autoTeam Structure Insights from ISO/SAE 21434 Development: The Organizational Key to Automotive Cybersecurity Compliance in Taiwan
Using the ISO/SAE 21434 development process as a case study, Zhang Hengwei's research reveals that team structure is the most critical IPO factor affecting international standard quality. For Taiwan's automotive suppliers, this means the success of TISAX certification and ISO/SAE 21434 implementation hinges on establishing a cross-functional cybersecurity governance team.
autoOptimizing Early-Stage Automotive Cybersecurity Process Design: A Practical Analysis of ISO/SAE 21434 and TISAX Compliance
Research by Christine Jakobs (2023) reveals systemic gaps in the early design phase of the automotive cybersecurity V-Model, leading to an incomplete ISO/SAE 21434 compliance evidence chain. The study proposes a function-oriented risk analysis method to identify threats before system architecture is finalized. This approach is crucial for Taiwanese suppliers preparing for TISAX certification and complying with UNECE WP.29 UN-R155 regulations, offering a practical framework to strengthen early-stage security practices and ensure robust compliance.
autoProposing HEAVENS 2.0: An Automotive Risk Assessment Model – Winners Consulting Services Insights
Winners Consulting Services Co., Ltd. highlights HEAVENS 2.0 as the vehicle risk assessment model that most closely aligns with ISO/SAE 21434 requirements. The research team systematically identified 17 model updates—12 to address compliance gaps and 5 to remediate weaknesses—fully aligning the original HEAVENS framework with mandatory UN R155 regulations. This provides a clear gap analysis checklist for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 implementation.
autoAMCSF: New Cloud Compliance Requirements for ISO 21434 and TISAX
Geol Kang's 2025 Automotive Multi-Cloud Security Framework (AMCSF) reveals that in the era of Software-Defined Vehicles, the primary attack surface has shifted from the vehicle to the cloud backend. The five-layer defense architecture integrates the ISO/SAE 21434 lifecycle and emphasizes the necessity of CSPM tools. Taiwanese OEMs and Tier-1/Tier-2 suppliers must incorporate cloud security into their TISAX assessment preparations to meet these evolving compliance demands and secure their position in the supply chain.
autoISO/SAE 21434 Gap Analysis: Systematically Strengthening TARA Management and Incident Handling
A 2023 arXiv paper reveals systemic gaps in ISO/SAE 21434 concerning cross-supply chain TARA management and vulnerability incident handling, proposing 13 new terms and 4 new process steps. Taiwanese automotive suppliers, during TISAX certification and UNECE WP.29 compliance, should prioritize strengthening post-production incident response and TARA lifecycle management. Winners Consulting Services offers a 90-day implementation plan to address these critical areas and ensure robust compliance.
autoQuantifying Systemic Cybersecurity Impacts of Connected Vehicles: A Key Extension for ISO 21434 TARA
The current ISO/SAE 21434 TARA framework, limited to a single-vehicle boundary, fails to quantify the cascading impacts of connected vehicles on the entire traffic system. A new study simulates three attack scenarios, introducing for the first time systemic operational and safety impact vectors to provide an objective basis for TARA impact ratings. Taiwanese automotive suppliers pursuing TISAX certification and UNECE WP.29 compliance must incorporate this systemic risk perspective into their threat analysis to meet evolving OEM requirements and enhance the defensibility of their cybersecurity management systems.
autoAn Adaptable Security-by-Design Approach — Winners Consulting Services Insights
Winners Consulting Services Co., Ltd. highlights a 2025 study by UK scholar Jeremy Bryans et al., which is the first to systematically apply the Security-by-Design concept from ISO/SAE 21434 to the entire lifecycle of vehicle OTA updates. The research integrates Threat Analysis and Risk Assessment (TARA) with UNECE WP.29 mitigation requirements, offering a practical framework for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 compliance.
FAQ
ISA2027 什麼時候開始適用?
2027 年 1 月 1 日起委託的 TISAX 評估一律適用 ISA2027;2026 年 12 月 31 日前委託者仍可依 ISA 6.0.3 完成。判斷依據是委託日,不是評估日。
已經取得的 TISAX 標籤會失效嗎?
不會。既有標籤維持原效期(最長三年),ISA2027 不要求提前複評;到期後的下一次評估,再依委託日決定適用版本。
TISAX 是認證嗎?
嚴格來說不是。TISAX 是由 ENX 協會營運的評估與交換機制,評估由 ENX 核准的稽核服務商執行,通過後取得的是在 ENX 平台共享的評估標籤,不是 ISO 證書。市場上習稱的「TISAX 認證」,指的就是這個標籤。
原型保護的標籤有什麼變化?
ISA2027 只保留兩種原型保護標籤:Basic(AL2)證明具備安全處理原型件與原型車的流程與人員;Facilities(AL3)再加上場址的實體防護,並涵蓋 Basic 的全部要求。控制項由 22 項精簡為 20 項,重新分為組織與實體兩節。
TISAX 和 ISO/SAE 21434 有什麼關係?
TISAX 著重資訊安全管理(供應鏈機密資料保護),ISO/SAE 21434 著重車輛產品開發全生命週期的網路安全工程(TARA 威脅分析、CSMS)。兩者互補而非取代;積穗科研提供整合輔導,共用底稿以節省重複建置成本。
Tier 2 供應商也需要 TISAX 嗎?
當 Tier 1 客戶要求其供應商提供 TISAX 評估結果時,Tier 2 同樣需要完成評估。積穗科研已輔導台灣車用散熱系統廠與鋁合金加工廠完成 TISAX 評估,熟悉 Tier 2 的評估重點與文件要求。
TISAX 評估準備需要多久?
依企業現有資安成熟度,輔導期通常為 7–12 個月以上;已持有 ISO 27001 的企業可縮短準備週期。評估範圍含原型保護、且預計 2027 年後委託者,需預留依 ISA2027 重構文件的時間。積穗科研在免費機制診斷後提供時程規劃。