As the automotive industry advances toward software-defined vehicles and AI-driven engineering workflows, information security has become a fundamental prerequisite. CYMETRIS has completed its TISAX® assessment, meeting the information security standards increasingly expected of software platforms across the automotive supply chain.
TISAX® (Trusted Information Security Assessment Exchange), administered by the ENX Association on behalf of the German Association of the Automotive Industry (VDA), has become a central mechanism for standardized information security assessments within automotive development ecosystems. The framework was designed to enable secure collaboration between OEMs, suppliers, engineering service providers, and technology partners handling sensitive development and vehicle-related data.
For CYMETRIS, completing the assessment represents more than a formal milestone. Cyber risk analysis and TARA methodology are inherently tied to sensitive development data, supply chain collaboration, and complex engineering workflows, making information security, confidentiality, and controlled data handling foundational requirements for trustworthy platform operation.
Platform-Driven: CYMETRIS Used Its Own Solution to Complete the Required Risk Assessment
The TISAX® assessment process demands a structured information security risk assessment covering asset identification, threat modeling, and the evaluation of organizational and technical controls in line with VDA ISA requirements. CYMETRIS conducted this process using its own platform, including automated tracking of open findings and direct Jira integration for remediation workflows.
This was a deliberate step as part of broader efforts to validate CYMETRIS beyond its established ISO/SAE 21434 TARA use case. The platform is increasingly being adopted for adjacent risk assessment frameworks, including CRA-aligned assessments and engineering environments in sectors such as agriculture and two-wheeled vehicles, where teams find that CYMETRIS maps cleanly to their specific methodological needs. The TISAX® exercise confirmed that the platform provides sufficient flexibility and structure to support these expanding use cases reliably.
Enabling Secure Collaboration at Scale
The TISAX® status strengthens CYMETRIS as a reliable platform partner for regulated automotive environments, particularly in contexts involving co-development, distributed engineering organizations, and safety-critical product data.
“Many are talking about AI, SDVs, and automated workflows right now. At the same time, it is often underestimated that these developments only work if the underlying infrastructure and organization remain protected. With TISAX®, we create exactly that foundation for CYMETRIS as a prerequisite for our continued growth as a partner for integrated cybersecurity engineering.”
— Philipp Veronesi, Founder and Managing Director, CYMETRIS
“The future of cyber risk assessment and TARA lies in dynamic, interconnected engineering processes. That shift significantly raises the bar for traceability, access control, and information protection. TISAX® supports our commitment to building CYMETRIS as a robust platform for safety- and security-critical development environments, in line with what the industry demands.”
— Falk Mayer, Co-Founder and Managing Director, CYMETRIS
The TISAX® assessment confirms that CYMETRIS meets established requirements for information security, controlled data access, and structured governance, reinforcing the foundation for scaling the platform across complex OEM, supplier, and multi-partner environments where secure collaboration and controlled information flows are essential.
TISAX® is a registered trademark of the ENX Association. ENX Association does not take any responsibility for any content shown on this website.
Stay up to date with CYMETRIS and our software platform. We regularly share new features, updates, and practical expert insights on cyber risk assessment and TARA. Browse all our latest posts right here: NEWS
How can TARA function across organizational boundaries? Through intelligent nesting. We recently published an expert blog on this topic, available in the Knowledge Hub of the CYEQT Knowledge Base, the leading training platform for automotive cybersecurity. LEARN MORE↗
We are currently developing our first customer success stories featuring clients who have already successfully integrated the CYMETRIS platform into their development workflows. Check back here soon for detailed insights and comprehensive case studies. LEARN MORE↗
Many automotive TARAs remain isolated in Excel, disconnected from development workflows. This CYEQT Knowledge Base article reveals the gaps between risk analysis and implementation, explains TARA integration, and provides actionable steps to achieve genuine traceability across your toolchain. LEARN MORE↗
TARA (Threat Analysis and Risk Assessment) provides a powerful methodology for systematically identifying and evaluating cyber risks — throughout product development and across the entire lifecycle.
Our overview page guides you step-by-step through the complete TARA process in line with ISO/SAE 21434: you’ll learn which phases matter, what artifacts play a role, and what truly counts.
What you’ll find here:
Get started now and dive into the full guide.
Our platform continues to evolve with cutting-edge features for intelligent cyber risk modeling/TARA. Want the latest on new capabilities, integrations, and industry developments? Reach out to our team for insights tailored to your needs.
Adding {{itemName}} to cart
Added {{itemName}} to cart