TISAX® AL3: Understanding requirements and assessments
Understand TISAX AL3 and prepare the right technical measures
In the automotive environment, information must be protected along the cooperation process. TISAX enables the exchange of assessment results. Assessment Level 3 describes the intensity of the examination.

What this means for your IT project
At AL3, an approved audit provider comprehensively verifies the applicable requirements, including on-site activities. The assessment level must be considered together with the objectives, scope and actual result. AL3 alone is not a universal security certificate.
For a technical project, the requirements of your business partner are the appropriate starting point. SYNEDAT can clarify with you which systems, access and operating procedures are affected and which technical measures belong in a realistic implementation plan.
Specify the business partner's requirement
For a project, the expected evidence and the activities concerned should be clearly described. We help with the technical classification: What data is processed where and which internal or external teams are involved?
Structuring Environments and Access
Separate project areas, appropriate permissions, and controlled administrative access can be essential for collaboration. Appropriate actions depend on data, processes, and existing infrastructure.
Implementing technical measures in a comprehensible way
A prioritized list of measures can be used to create concrete work packages: such as hardening, endpoint management, logging or the protection of interfaces. Agreed test steps make the implementation status visible.
Combining operation and verification
Responsible teams need clear documentation and repeatable processes. Operational records, approval paths and defined procedures for security incidents should therefore be part of the technical handover.
Frequently Asked Questions
What does TISAX AL3 mean?
AL3 stands for Assessment Level 3 and refers to a comprehensive examination of applicable requirements with on-site activities. TISAX is a procedure for the exchange of assessment results.
Why is the AL3 specification not sufficient for a supplier audit?
It must be considered together with assessment objectives, scope and result. The decisive factor for your project is whether the activities and locations actually affected are within the relevant area of application.
How are assessment results shared?
Participants share results with the intended partners via the ENX portal. The release is based on the exchange procedure regulated there.
Where should a technical preparation project start?
With an overview of the relevant systems, data flows, responsible persons and requirements of your business partner. From this, the technical need for action can be prioritized together.
Which infrastructure topics can be relevant?
Depending on the initial situation, this includes identities, endpoints, network segmentation, administrative access, logging and recovery. The specific scope is determined based on your environment.
Does the entire IT have to be changed at once?
Technical improvements can be divided into coordinated work packages. Dependencies, operational effects and necessary evidence determine the sequence.
How does SYNEDAT support the implementation?
We can design, implement and document agreed technical measures and pass on knowledge to your team. The independent assessment is carried out by the responsible testing service provider.
What information helps with an inquiry?
The specific partner requirements, affected locations and processes, existing documents and desired deadlines are helpful. We exchange confidential documents via an agreed, suitable channel.
Specify requirements at an early stage
Bring your requirements from purchasing, information security or quality management into the initial meeting. Together we assign them to the planned scope of services.
Discuss requirementsOfficial information
TISAX® is a registered trademark of the ENX Association.