TISAX® labels are generally valid for three years.
The three years are calculated from the end of the assessment process (closing meeting on the last audit day), regardless of whether you have completed the assessment with or without deviations. We therefore always recommend our customers to start renewing their TISAX® label at least one year before the expiry date. This saves you waiting times and possible difficulties in acquiring new orders that require TISAX®.
At the end of the three years, the label must be renewed.
To do this, the TISAX® process must be carried out again. To do this, companies must register a new scope in the ENX portal, undergo a new assessment with the new scope ID by an approved assessment service provider and share the assessment result with partners and customers on ENX.
As with any management system, a continuous improvement process must be ensured, which is why companies that have already been certified according to TISAX® should provide evidence of ongoing and sustainable active use of the defined ISMS processes. The Deming principle (PDCA cycle), for example, can be used to establish this in a resource-saving and cost-efficient manner.
- Plan: This involves defining the company objectives and the top management's information security objectives for the coming period at regular intervals, carrying out an internal audit, also known as a scope and gap analysis, and performing a risk analysis in order to compare the current and target status. As a result of these analyses and the planning phases, measures are defined and transferred into a scheduled action plan.
- Do: In this phase, the goals set and measures defined in the planning phase are developed and implemented. Attention must be paid to regular sensitization of employees and communication of the new regulations.
- Check: In order to monitor and continuously improve the effectiveness of the defined processes, key figures must be collected and threshold values defined. For example, a penetration test or simulated incidents and phishing campaigns can be used to examine the effectiveness of technical and organizational measures and employee awareness.
- Act: The various reviews and feedback from employees and process owners may indicate that objectives, guidelines and processes need to be redesigned, optimized or withdrawn. This optimization phase helps to continuously improve the company's security strategy and increase the level of security maturity.
Do you have questions about the process? Are you facing the recertification process or do you lack the time and resources to make your ISMS sustainable?


