- No. ISMS evidence is required only from suppliers, considered relevant based on the information, systems, documentation, products or activities involved in the business relationship.
Overview of ISMS
ZF is committed to protecting confidential information, systems and intellectual property throughout its supply chain.
Suppliers that handle confidential ZF information, access ZF systems, receive confidential ZF documentation or provide ZF-specific products or services may be required to provide evidence of an appropriate Information Security Management System (ISMS).
This requirement can be demonstrated through:
- a valid TISAX assessment (or)
- where accepted by ZF, an ISO/IEC 27001:2022 certificate whose certified scope fully covers the relevant business relationship with ZF.
TISAX stands for Trusted Information Security Assessment Exchange. It is the automotive-industry mechanism used to assess information-security requirements and share assessment results through the ENX platform.
For further information, please visit the ENX TISAX homepage:
TISAX Governance
The ENX Association is the governing organization behind the TISAX certification. This organization was formed in 2000 by European automobile manufacturers, automotive suppliers, and a number of national automobile associations to define and oversee industry standards.
Why does ZF require ISMS evidence
ZF exchanges confidential information and business-relevant data with suppliers throughout the sourcing and delivery processes.
Appropriate information-security controls are therefore necessary to protect ZF information and meet applicable customer and business requirements across the supply chain.
Which suppliers are ISMS relevant?
Not every supplier is required to provide ISMS evidence.
A supplier may be considered ISMS relevant if one or more of the following criteria apply:
- The supplier works with confidential ZF information.
- The supplier has access to ZF systems or information.
- The supplier receives, stores or processes sensitive ZF documentation, such as drawings, prints or intellectual property.
- The supplier provides parts, products or services based on specific ZF requirements.
Your responsible ZF buyer will inform you if ISMS evidence is required. Please contact your buyer if you are unsure whether your company is ISMS relevant.
What evidence is required?
TISAX Assessment Objectives and Assessment Levels
TISAX defines different assessment objectives depending on the protection needs and type of information involved. Each assessment objective is associated with an applicable assessment level.
The table below shows the 12 different TISAX assessment objectives:
The table below shows the 12 different TISAX assessment objectives which are currently offered by the certification body ENX. The assessment objective determines the applicable requirements that the information security management system (ISMS) has to fulfill. The assessment objective is entirely based on the type of data you handle on behalf of ZF. The ones marked with “ZF” have to be checked within the business relationship with ZF whether they are mandatory or not. For the module „Information Security” the ZF requires as a minimum: „Info high” / „ Confidential”/ „High availability”.
The applicable assessment objectives depend on the information, systems, products and activities involved in the business relationship with ZF.
A valid ISO/IEC 27001:2022 certificate may be accepted by ZF as alternative or interim ISMS evidence if the certified scope fully covers the relevant sites, processes and activities related to the supplier’s business with ZF.
1. TISAX
After completing the required TISAX assessment level, supplier has to make the relevant assessment results available to ZF through the ENX portal.
Use the following ZF participant ID: PLZRCC
2. ISO/IEC 27001:2022
Where ISO/IEC 27001:2022 is accepted by ZF, upload the following information in the “Certificates” section of the SupplyOn Business Directory:
- the valid ISO/IEC 27001:2022 certificate;
- the certified scope
- the certificate validity information
The supplier shall monitor the validity of its ISO/IEC 27001:2022 certificate and upload the renewed certificate into SupplyOn before the previous certificate expires; failure to provide relevant ISMS evidence when necessary may impact the supplier’s evaluation in the sourcing process.
Frequently Asked Questions
- The responsible ZF buyer will inform supplier if ISMS evidence is required.
- Should there be any questions regarding the applicability of TISAX, the supplier may contact its ZF buyer for further assistance.
- In general, suppliers identified as ISMS relevant are expected to meet at least Assessment Level 2 (AL2) with applicable assessment objectives such as “Confidential” and “High availability.”
- Depending on the business relationship and protection needs, additional assessment objectives for Data Protection and/or Prototype Protection may apply. The applicable assessment level (AL2 or AL3) depends on the respective assessment objective and will be communicated by the responsible ZF buyer.
- Yes, where accepted by ZF.
- The certified scope must fully cover the relevant sites, processes and activities involved in the business relationship with ZF.
- No. Suppliers are responsible for the costs associated with their TISAX assessment and related audit activities.
- Make the relevant assessment result available to ZF through the ENX portal using the ZF participant ID: PLZRCC
- For information about TISAX, the assessment process and approved audit providers, please visit the ENX TISAX homepage:
- For ZF-specific requirements, please contact your responsible ZF buyer.
- This depends on the scope.
- The assessment or certificate must cover all locations, processes and activities relevant to the business relationship with ZF. Responsible ZF buyer is to be contacted if the scope is unclear.