Automotive Industry Standard

TISAX Compliance Services

Achieve TISAX certification and maintain your place in the global automotive supply chain. We help suppliers meet the information security requirements of Volkswagen, BMW, Mercedes-Benz, Porsche, Audi, and the entire VDA ecosystem.

ENX-Accredited Approach
VDA ISA Expertise
Automotive Industry Focus
3-Year Label Validity

What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standardized assessment and exchange mechanism for information security. Developed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA), TISAX enables OEMs and suppliers to verify and share information security assessment results through a trusted, centralized platform.

The assessment is based on the VDA ISA (Information Security Assessment) catalog, which extends ISO 27001 requirements with automotive-specific criteria for prototype protection, supply chain interfaces, and data protection. A valid TISAX label is now a contractual prerequisite for doing business with major German automotive manufacturers.

VDA ISA Based

Built on ISO 27001 with automotive-specific controls

Global Recognition

Accepted across all ENX member OEMs worldwide

Secure Exchange

Controlled sharing via the ENX portal

3-Year Validity

Label valid for 3 years with annual confirmations

Who Requires TISAX?

Volkswagen Group

VW, Audi, Porsche, Bentley, Lamborghini

BMW Group

BMW, Mini, Rolls-Royce

Mercedes-Benz Group

Mercedes-Benz, AMG, Smart

Tier 1 Suppliers

Bosch, Continental, ZF, Magna, Denso

Tier 2/3 Suppliers

Sub-component and raw material suppliers

TISAX Assessment Levels

Three assessment levels define the depth of evaluation required based on the sensitivity of information handled and OEM contractual requirements.

Assessment Level 1 — Normal

Basic self-assessment based on a standardized questionnaire for lower-risk scenarios

  • Self-assessment using ENX standardized questionnaire
  • Suitable for suppliers handling limited sensitive data
  • No external audit required
  • Quick validation for non-critical supply chain partners

Assessment Level 2 — High

On-site audit by an accredited auditor evaluating implemented information security controls

  • On-site audit by an ENX-accredited audit provider
  • In-depth review of VDA ISA control implementation
  • Required for most Tier 1 and Tier 2 suppliers
  • Valid for 3 years with annual self-confirmations

Assessment Level 3 — Very High

Extensive on-site audit with additional evidence review for highly sensitive data environments

  • Detailed on-site audit with extended scope and evidence review
  • Required for prototype protection and highly sensitive CUI
  • Comprehensive documentation and evidence requirements
  • Maximum assurance for OEM direct suppliers

Assessment Scope & Objectives

TISAX defines specific assessment objectives tailored to automotive industry needs

  • Information Security (based on VDA ISA / ISO 27001)
  • Connection to Third Parties (supply chain interfaces)
  • Data Protection (GDPR alignment for personal data)
  • Prototype Protection (design and engineering confidentiality)

VDA ISA Control Domains

The VDA ISA catalog comprises 14 control domains with 91+ individual controls based on ISO 27001:2022 Annex A, tailored for the automotive industry.

1

Information Security Policy

4 controls

2

Organization of Information Security

7 controls

3

Human Resources Security

7 controls

4

Asset Management

6 controls

5

Access Control

9 controls

6

Cryptography

3 controls

7

Physical Security

8 controls

8

Operations Security

10 controls

9

Communications Security

7 controls

10

System Development & Maintenance

7 controls

11

Supplier Relationships

7 controls

12

Incident Management

5 controls

13

Business Continuity

5 controls

14

Compliance

6 controls

Our TISAX Implementation Process

A structured, proven approach to guide your organization from initial assessment through TISAX label issuance.

Phase 1

Scope & Gap Analysis

Weeks 1-3

Define TISAX assessment scope, identify relevant VDA ISA requirements, and evaluate your current security posture against automotive industry standards.

Phase 2

Remediation & Implementation

Weeks 4-14

Implement required security controls, develop TISAX-specific policies and procedures, and build evidence documentation for audit readiness.

Phase 3

Internal Audit & Readiness

Weeks 15-18

Conduct internal pre-assessment audits, close remaining gaps, prepare evidence packages, and register for TISAX assessment with ENX.

Phase 4

TISAX Assessment & Exchange

Weeks 19-24

Complete the accredited TISAX audit, address any findings, obtain your TISAX label, and publish results for sharing with automotive partners.

Benefits of TISAX Certification

TISAX certification delivers more than regulatory compliance — it strengthens your competitive position in the global automotive supply chain.

  • Maintain eligibility to bid on contracts with Volkswagen, BMW, Mercedes-Benz, Porsche, and Audi
  • Demonstrate information security maturity to the entire VDA supply chain
  • Reduce redundant audits — one TISAX assessment accepted across all ENX member OEMs
  • Align with ISO 27001 while meeting automotive-specific prototype and data protection requirements
  • Protect sensitive design, engineering, and manufacturing data from intellectual property theft
  • Meet contractual information security requirements for Tier 1, 2, and 3 automotive suppliers
3x

Faster than multiple OEM-specific audits

3yr

Label validity with annual confirmations

10+

Major OEMs accepting TISAX results

91+

VDA ISA controls assessed

Industries We Serve

TISAX requirements extend across every layer of the automotive supply chain — from raw materials to finished vehicles.

OEMs & Vehicle Manufacturers

Passenger car, commercial vehicle, and EV manufacturers requiring supply chain security

Tier 1 Suppliers

Major component suppliers — drivetrain, chassis, electronics, and interior systems

Tier 2/3 Suppliers

Sub-component, raw material, and specialty part suppliers in the automotive value chain

Engineering & R&D Services

Design studios, prototyping firms, and engineering consultancies handling confidential IP

Logistics & Supply Chain

Warehousing, transportation, and just-in-sequence delivery service providers

Software & IT Services

Automotive software developers, cloud service providers, and connected vehicle platforms

Ready to Achieve TISAX Certification?

Don't let information security requirements block your automotive contracts. Our TISAX experts will guide you from gap analysis through label issuance — with a process tailored to your organization size and OEM requirements.

Frequently Asked Questions

Common questions about TISAX compliance, costs, timelines, and requirements.

Still Have Questions?

Our cybersecurity experts are here to help. Get personalized answers and a free security consultation.