Requirements
What the regulation expects

Required by major OEMs
VW, BMW, Mercedes and their supply chains expect TISAX. AL3 is the highest assessment level.
Prototype and design data
High-value engineering and prototype information needs encryption with keys the supplier and OEM can govern.
Third-party connections
OEM and tier-N integrations still need controlled key access and auditable handoffs.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Central key policy, inventory and audit for engineering and production systems.
Learn moreAutomotive cyber security
External key control for systems that leave the corporate data centre.
Learn moreKey themes
Where independent key control fits
Status: TISAX AL3 certified. Certificate available on request.
Information security management
ISMS-aligned key and access controls with exportable evidence for TISAX assessors and OEM questionnaires.
Prototype protection
Encryption with customer-held or programme-held keys for design and prototype data stores.
Data protection requirements
Access control, encryption at rest and in transit, and retention-aware key lifecycle.
Connection to third parties
Tenant scoping, per-key access policy and audit trails for OEM and supplier integrations.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
