What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standardized assessment and exchange mechanism for information security. Developed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA), TISAX enables OEMs and suppliers to verify and share information security assessment results through a trusted, centralized platform.
The assessment is based on the VDA ISA (Information Security Assessment) catalog, which extends ISO 27001 requirements with automotive-specific criteria for prototype protection, supply chain interfaces, and data protection. A valid TISAX label is now a contractual prerequisite for doing business with major German automotive manufacturers.
VDA ISA Based
Built on ISO 27001 with automotive-specific controls
Global Recognition
Accepted across all ENX member OEMs worldwide
Secure Exchange
Controlled sharing via the ENX portal
3-Year Validity
Label valid for 3 years with annual confirmations
Who Requires TISAX?
VW, Audi, Porsche, Bentley, Lamborghini
BMW, Mini, Rolls-Royce
Mercedes-Benz, AMG, Smart
Bosch, Continental, ZF, Magna, Denso
Sub-component and raw material suppliers
TISAX Assessment Levels
Three assessment levels define the depth of evaluation required based on the sensitivity of information handled and OEM contractual requirements.
Assessment Level 1 — Normal
Basic self-assessment based on a standardized questionnaire for lower-risk scenarios
- Self-assessment using ENX standardized questionnaire
- Suitable for suppliers handling limited sensitive data
- No external audit required
- Quick validation for non-critical supply chain partners
Assessment Level 2 — High
On-site audit by an accredited auditor evaluating implemented information security controls
- On-site audit by an ENX-accredited audit provider
- In-depth review of VDA ISA control implementation
- Required for most Tier 1 and Tier 2 suppliers
- Valid for 3 years with annual self-confirmations
Assessment Level 3 — Very High
Extensive on-site audit with additional evidence review for highly sensitive data environments
- Detailed on-site audit with extended scope and evidence review
- Required for prototype protection and highly sensitive CUI
- Comprehensive documentation and evidence requirements
- Maximum assurance for OEM direct suppliers
Assessment Scope & Objectives
TISAX defines specific assessment objectives tailored to automotive industry needs
- Information Security (based on VDA ISA / ISO 27001)
- Connection to Third Parties (supply chain interfaces)
- Data Protection (GDPR alignment for personal data)
- Prototype Protection (design and engineering confidentiality)
VDA ISA Control Domains
The VDA ISA catalog comprises 14 control domains with 91+ individual controls based on ISO 27001:2022 Annex A, tailored for the automotive industry.
Information Security Policy
4 controls
Organization of Information Security
7 controls
Human Resources Security
7 controls
Asset Management
6 controls
Access Control
9 controls
Cryptography
3 controls
Physical Security
8 controls
Operations Security
10 controls
Communications Security
7 controls
System Development & Maintenance
7 controls
Supplier Relationships
7 controls
Incident Management
5 controls
Business Continuity
5 controls
Compliance
6 controls
Our TISAX Implementation Process
A structured, proven approach to guide your organization from initial assessment through TISAX label issuance.
Scope & Gap Analysis
Define TISAX assessment scope, identify relevant VDA ISA requirements, and evaluate your current security posture against automotive industry standards.
Remediation & Implementation
Implement required security controls, develop TISAX-specific policies and procedures, and build evidence documentation for audit readiness.
Internal Audit & Readiness
Conduct internal pre-assessment audits, close remaining gaps, prepare evidence packages, and register for TISAX assessment with ENX.
TISAX Assessment & Exchange
Complete the accredited TISAX audit, address any findings, obtain your TISAX label, and publish results for sharing with automotive partners.
Benefits of TISAX Certification
TISAX certification delivers more than regulatory compliance — it strengthens your competitive position in the global automotive supply chain.
- Maintain eligibility to bid on contracts with Volkswagen, BMW, Mercedes-Benz, Porsche, and Audi
- Demonstrate information security maturity to the entire VDA supply chain
- Reduce redundant audits — one TISAX assessment accepted across all ENX member OEMs
- Align with ISO 27001 while meeting automotive-specific prototype and data protection requirements
- Protect sensitive design, engineering, and manufacturing data from intellectual property theft
- Meet contractual information security requirements for Tier 1, 2, and 3 automotive suppliers
Faster than multiple OEM-specific audits
Label validity with annual confirmations
Major OEMs accepting TISAX results
VDA ISA controls assessed
Industries We Serve
TISAX requirements extend across every layer of the automotive supply chain — from raw materials to finished vehicles.
OEMs & Vehicle Manufacturers
Passenger car, commercial vehicle, and EV manufacturers requiring supply chain security
Tier 1 Suppliers
Major component suppliers — drivetrain, chassis, electronics, and interior systems
Tier 2/3 Suppliers
Sub-component, raw material, and specialty part suppliers in the automotive value chain
Engineering & R&D Services
Design studios, prototyping firms, and engineering consultancies handling confidential IP
Logistics & Supply Chain
Warehousing, transportation, and just-in-sequence delivery service providers
Software & IT Services
Automotive software developers, cloud service providers, and connected vehicle platforms
Frequently Asked Questions
Common questions about TISAX compliance, costs, timelines, and requirements.
Still Have Questions?
Our cybersecurity experts are here to help. Get personalized answers and a free security consultation.