- Work with confidential ZF data
- Have system access to ZF information
- Obtain copies of sensitive ZF documentation (e.g. drawings)
- Provide parts specific to ZF requirements
TISAX, or Trusted Information Security Assessment Exchange, is a certification standard that is used to evaluate a company’s ability to meet all information security process standards throughout the entire organization.
Evaluation is done in the following areas:
While originally driven by European OEMs/Tier 1 suppliers, the certification is now a global standard and is required by ZF.
To learn more, please visit the ENX TISAX Homepage
The TISAX standard seeks to establish a mature Information Security level in the automotive industry by creating a mutually accepted certificate for suppliers under one global standard. By creating one common standard, the aim is to reduce cost, effort and complexity for all participants and allow for comparable results between participants.
The ENX Association is the governing organization behind the TISAX certification. This organization was formed in 2000 by European automobile manufacturers, automotive suppliers, and a number of national automobile associations to define and oversee industry standards. To learn more, about ENX, please visit their website.
In our connected and information-driven business environment it is critical that proper information safeguards are in place. Many of ZF's customers have included TISAX requirements in their Terms & Conditions, which require us (and our supply chain) to prove a mature Information Security Management System (ISMS). ZF Group has already worked to certify many of our locations based on customer requirements and risk analysis. Beginning in 2020 we began implementation of a TISAX certification requirement for those suppliers who met the applicable criteria. For suppliers deemed TISAX relevant by ZF, maintenance of a proper TISAX certification in SupplyOn Business Directory is a condition of sourcing.
ZF Group's commitment to the TISAX standard and our intention to implement this with our supply base were communicated a supplier letter distributed in August 2020. Click here to read the communication.
Not all suppliers are considered "TISAX Relevant" by ZF Group. For TISAX to be required, a supplier must meet one or more of the following criteria:
If the necessary criteria is met, ZF Group will designate a supplier as "TISAX Relevant" and your supplier ID will receive a flag in our systems. You will be notified directly by your ZF Group buyer if certification is a requirement so that you can provide an existing certification or begin the process.
There are three Assessment levels outlined in the TISAX certification, however ZF requires Assement level 3 (AL3)
Based on the assessment objectives that apply to the ZF-supplier relationship, it is clear that only Assessment Level 3 is acceptable.