We assess other companies for a living. Then we went through a TISAX assessment ourselves.
SEVN-X spends its days on the assessor's side of the table, reviewing controls, asking for evidence, and pressure-testing how other organizations run security. Going through TISAX flipped that dynamic. In the video above, Shade sits down with Matt Wilson to talk about what it was really like to be the one under scrutiny, where the team's confidence helped, and where it got in the way.
Watch the full conversation
Questions covered in this interview
- What was it like to be the one being assessed?
- Did you assume it would be easy because of your day job?
- Did the assessor show you any tricks you'd steal for your own work?
- What were you most confident about that turned out to be the toughest?
- What took longer than expected?
- How honest were you on the first pass of the self-assessment?
- What's the difference between a document that exists and one that survives an assessment?
- What's the cost nobody puts in the budget?
- Who inside SEVN-X had the hardest job?
Preparing for TISAX or another security assessment?
Talk to a team that has sat on both sides of the table, and knows what assessors actually look for.
Talk to our teamWhat is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the information security assessment and exchange mechanism used across the automotive industry. It's governed by the ENX Association and built on the VDA Information Security Assessment (ISA) catalog. Automotive manufacturers commonly require suppliers and service providers that handle their sensitive information to complete a TISAX assessment, and results are shared through the ENX portal as assessment labels rather than a traditional certificate.
Confidence is good. Overconfidence is not.
Walking in, the team's instinct was simple: we know this material, so how hard can it be? Controls are controls, and the content, questions, and process were all familiar. But knowing the subject matter is not the same as doing the work of an assessment. Documentation still has to be gathered, responses still have to be written and refined, and every answer still has to land with a reader who has never seen your environment. As Matt puts it, be humble or be humbled.
The Goldilocks problem with control responses
The toughest part was one the team had done countless times for clients: answering a questionnaire. Each control needs a response at exactly the right depth. Too little and the assessor has more questions. Too much and the answer buries what matters. Finding that middle ground takes time, because you're trying to anticipate what a specific assessor will care about in a specific control. The assessor helped along the way, but it was still harder than expected.
The assessor also ran the entire engagement through a single platform for communication and document uploads. It kept everything in one place and saved time, though after enough uploads it also gave the team a real appreciation for what their own clients go through on the receiving end of a portal.
Knowing a control is not the same as evidencing it
Even at a small firm, knowledge about how something is set up, configured, and owned is spread across people. Every answer meant tracking down the right person and confirming the evidence actually existed. There's a real gap between feeling confident about how a control works and proving it to an auditor's satisfaction. Closing that gap is where most of the time went, and it's why the process took longer than the team first planned for.
The team also committed to honesty from the very first pass of the self-assessment. A good assessor has a feel for answers that don't add up, and trying to polish over a weak spot usually creates more questions and more effort than simply stating the reality.
Documents that survive an assessment have teeth
A document that exists can say nice things that don't functionally mean anything. A document that survives an assessment is specific. Take an incident response plan. Saying you have one is cursory. A plan with teeth defines what counts as an incident, lays out the escalation path, and walks through likely scenarios and the first steps for each. That level of specificity isn't just for the assessor. It's what makes the document usable to your own team when it matters, whether it's a high-level security policy, a change management process, or an incident response plan.
The cost nobody puts in the budget
The assessment fee itself came in lower than expected. The real cost was people. Pulling three to five staff away from their regular work for a couple of hours every week adds up quickly, especially in a smaller organization, and it never shows up as a line item. Many organizations preparing for TISAX face the same reality: a small security or IT team, no dedicated assessment staff, and everyone already wearing several hats.
That's also why every assessment needs a lead cat herder. Someone has to keep the work prioritized, keep the group moving, and make sure responses actually get finished alongside everyone's real jobs. Without that person, even a well-prepared team stalls.