TISAX Explained: Automotive Information Security Assessment for Suppliers
August 3, 2026 · by Pentevo
TISAX Explained: Automotive Information Security Assessment for Suppliers
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment framework for the automotive industry, operated by the ENX Association and based on the VDA ISA control catalogue. It produces a shared assessment result — not a public certificate — that automotive suppliers exchange with OEMs via a secure portal to prove their information security posture.
Automotive OEMs hand sensitive data to suppliers daily: CAD drawings, prototype schedules, crash-test results, personal data from connected-vehicle programs. A single breach at a Tier-2 supplier can cascade upstream, exposing unreleased vehicle designs and triggering liability across the supply chain. TISAX exists to give OEMs a standardised, audited answer to the question: "Can this supplier handle our data safely?"
If a customer contract, tender document, or pre-qualification questionnaire has asked you for a "TISAX result," this guide explains exactly what that means, what you must do, and what to expect.
Why TISAX Exists: The OEM Supply Chain Problem
Before TISAX, each OEM ran its own supplier security audit programme. BMW audited its suppliers. Volkswagen audited its suppliers. Daimler audited the same suppliers again. A large Tier-1 might endure ten overlapping audits per year, each using a slightly different questionnaire. The administrative overhead was enormous and the results were incomparable.
In 2017, the ENX Association — a neutral body founded by European automotive manufacturers and suppliers — launched TISAX in partnership with the Verband der Automobilindustrie (VDA). The framework gives one standardised assessment methodology, one result format, and one portal through which results can be shared with any requesting OEM. A supplier completes one TISAX assessment and shares the resulting token with every OEM customer who asks, rather than submitting to dozens of bespoke audits.
Today, BMW Group, Mercedes-Benz Group, Volkswagen Group (including Audi, Porsche, ŠKODA), Stellantis, Continental, Bosch, and most major automotive Tier-1 and Tier-2 suppliers either require TISAX or strongly prefer suppliers who hold a valid result.
The VDA ISA Catalogue: What TISAX Actually Measures
The VDA ISA (Information Security Assessment) is the control catalogue that defines what auditors check. Version 6.0, published in 2024, is the current catalogue. It is structured into domains, each covering a distinct risk area. Requirements within each domain are phrased as must/should statements, and auditors rate compliance on a maturity scale.
VDA ISA Domains
| Domain | Abbreviation | What It Covers |
|---|---|---|
| Information Security | IS | ISMS governance, access control, cryptography, operations security, incident management, physical security, supplier management |
| Prototype and Vehicle Protection | PT | Protection of physical and digital prototypes, test vehicles, camouflaged vehicles, test tracks |
| Data Center and Cloud Hosting | DC | Data center infrastructure, redundancy, environmental controls, hosting for third parties |
| Data Protection | DP | GDPR-aligned personal data handling requirements (added in recent ISA versions) |
The IS domain is mandatory for all TISAX assessments. PT applies when a supplier handles prototype vehicles or prototype-related digital data. DC applies to organizations providing hosting services to other automotive companies.
Auditors evaluate each control against a maturity model. A score of 0 means the control does not exist; a score of 3 (typically the minimum required for a passing result) means the control is documented, implemented, and demonstrably effective. Controls rated below the required maturity threshold generate findings that must be remediated before the assessment result is valid.
TISAX Assessment Levels: AL1, AL2, AL3
TISAX defines three assessment levels that determine the rigour and method of the audit. OEM contracts specify which level they require; do not assume AL1 is sufficient without checking your contractual obligation.
| Assessment Level | Audit Method | When It Is Required |
|---|---|---|
| AL1 | Self-assessment only — no on-site auditor involvement; the supplier completes the VDA ISA questionnaire independently | Low-sensitivity data; rarely accepted by major OEMs for primary supplier relationships |
| AL2 | On-site audit by an ENX-accredited assessment body; the most common requirement from BMW, VW Group, Mercedes, and Stellantis | Standard requirement for suppliers handling confidential information, technical drawings, or project data classified as "confidential" |
| AL3 | Inter-rater audit — two independent ENX-accredited assessors review findings for consistency; highest scrutiny | Suppliers handling prototype data, unreleased vehicle designs, highly sensitive personal data, or operating under special OEM prototype-protection programmes |
AL2 is the de facto baseline for most supplier contracts with a major OEM. If a contract says "TISAX required" without specifying a level, request clarification — assume AL2 until confirmed otherwise.
AL3 adds a second, independent assessor who reviews the primary assessor's findings before the result is finalised. This increases both cost and timeline but is non-negotiable when the OEM's classification of the information being handled demands it.
TISAX Labels: What Your Result Actually Says
TISAX results do not say "pass" or "fail" in the traditional sense. They attach labels to the assessment result that describe the information categories the supplier has been assessed against. An OEM looks at your labels to determine whether your result covers the type of data they are sharing with you.
| Label Category | Label Code | What It Covers |
|---|---|---|
| Information and Data Security — Normal | IS-N | Handling of confidential but non-critical information |
| Information and Data Security — High | IS-H | Handling of highly confidential OEM data |
| Information and Data Security — Very High | IS-VH | Handling of data requiring the highest protection (rare) |
| Prototype Protection | PT | Physical and digital prototype vehicle data |
| Prototype Protection — Strict | PT-S | Strict prototype programmes, including camouflage and embargo requirements |
| Data Center Hosting | DC | Hosting of automotive data center workloads |
The assessment result stored in the ENX portal is tagged with the applicable labels and the location(s) in scope. When you share your result with a customer, you share a result token — a reference number — not the underlying report. The customer's ENX account can then access the result summary.
This design means your full audit findings, deviations, and internal processes are never exposed to the OEM. The portal shows the result (label achieved, yes/no), the scope, and the validity date.
Results are valid for three years from the date of the assessment. After three years, a re-assessment is required. Some OEMs request interim confirmation of no significant changes in year two.
How the TISAX Assessment Process Works
The process has five stages. Understanding them before you begin helps you allocate time and budget correctly.
Stage 1 — Registration on the ENX Portal
The supplier registers at enx.com. Registration requires company information, the assessment scope (which locations, which label categories), and the requested assessment level. Registration fees apply (typically a few hundred euros per location).
Stage 2 — Selecting an ENX-Accredited Assessor
TISAX assessments must be conducted by an ENX-accredited assessment body. Not all ISO 27001 certification bodies are accredited for TISAX. The ENX website maintains a current list of accredited assessors. Assessors set their own fees; obtain at least two quotes. Factor in travel costs for multi-location scopes.
Stage 3 — Preparation and Pre-Assessment
The supplier completes the VDA ISA self-assessment questionnaire, documents controls, collects evidence, and remediates gaps. Most organizations at this stage engage an internal project team and, optionally, an external consultant to run gap analysis. This is the stage where most of the time (6 to 18 months) is spent.
Common preparation activities include:
- Defining and documenting information asset inventories
- Formalising access control policies and reviewing actual access rights
- Implementing and testing an information security incident management procedure
- Documenting supplier agreements that include security obligations
- Conducting a formal risk assessment aligned to VDA ISA requirements
Stage 4 — The On-Site Audit (AL2/AL3)
The accredited assessor visits the location(s) in scope. Audits typically last one to three days per location depending on size. The assessor reviews documentation, interviews staff, and tests controls. Findings are classified by severity. Minor deviations may be accepted with a corrective action plan; major deviations must be remediated before the result is finalised.
Stage 5 — Result Publication and Sharing
Once all findings are resolved to the assessor's satisfaction, the assessment body uploads the result to the ENX portal. The supplier can then generate a result token and share it with any requesting OEM or customer. The result is accessible only to parties the supplier explicitly authorises.
Typical timeline from registration to valid result: 4 to 6 months for organisations with an existing ISMS; 12 to 18 months for those starting from scratch.
TISAX vs ISO 27001: Overlaps and Differences
Many suppliers ask whether ISO 27001 certification exempts them from TISAX. It does not. The two frameworks are complementary, not interchangeable.
| Dimension | TISAX | ISO 27001 |
|---|---|---|
| Governing body | ENX Association (VDA methodology) | ISO / IEC |
| Output | Assessment result (shared via ENX portal) | Certificate issued by accredited certification body |
| Public visibility | No — result shared only with specified parties | Yes — certificate publicly verifiable |
| Industry focus | Automotive supply chain | General (any industry) |
| Control catalogue | VDA ISA v6.0 (2024) | ISO 27001 Annex A / ISO 27002 |
| Prototype protection | Explicit PT domain | Not addressed |
| Assessment levels | AL1 / AL2 / AL3 | Single certification level |
| Assessor requirement | ENX-accredited assessment body only | ISO 17021-1 accredited certification body |
| Validity period | 3 years (re-assessment required) | 3 years with annual surveillance audits |
| Result sharing mechanism | ENX portal token system | Certificate copy shared ad hoc |
Practical implication: If you hold ISO 27001, a TISAX assessor will typically accept your existing documented controls as evidence, reducing audit duration and effort. However, you will still need to address gaps specific to VDA ISA — particularly prototype protection, automotive-specific supplier chain requirements, and any VDA ISA controls not covered by ISO 27001 Annex A.
Common TISAX Audit Failure Points
Assessors consistently report the same categories of non-conformity across first-time TISAX audits.
Scope gaps. The assessment scope registered in the ENX portal excludes locations that actually handle OEM-relevant data — a home-office policy that allows employees to access confidential design files from unregistered locations, or a development office not included in the original registration. Every location where in-scope information is processed must be included.
Undocumented risk assessment. VDA ISA requires a formal, documented information security risk assessment tied to the organisation's asset inventory. Many suppliers perform informal risk management but cannot produce the artefact the assessor expects.
Supplier management gaps. VDA ISA requires that security obligations flow to the supplier's own suppliers (sub-processors, cloud providers, outsourced IT). Contracts that lack information security clauses are a recurring finding — particularly for cloud services where a supplier relies on a hyperscaler without a documented risk assessment or exit strategy.
Inadequate access review. Formal, documented periodic access rights reviews are required. Organisations that rely on informal processes — "we'd notice if something changed" — do not meet the maturity threshold.
Incident management without a test. Having an incident response procedure document is not sufficient. Assessors expect evidence that the procedure has been tested, typically through a tabletop exercise or drill. The test must be documented.
Physical security at all locations. Visitors registers, clean-desk enforcement, locked server room access logs — these are checked at every in-scope location, including satellite offices.
TISAX Assessment Costs
TISAX costs fall into two categories: assessor fees and preparation costs.
Assessor fees for an AL2 audit of a single headquarters location typically range from roughly $8,000 to $20,000. Multi-location scopes, additional label categories (PT, DC), and AL3 inter-rater requirements push fees toward $35,000 or higher. These are market-rate estimates; actual fees vary by assessor and geography. Request itemised quotes from at least two ENX-accredited bodies.
Preparation costs depend heavily on starting maturity:
- An organisation with a functioning ISO 27001-aligned ISMS may need only targeted gap remediation — budget for a few weeks of consultant time and tooling updates.
- An organisation starting with no formal ISMS should expect to invest significantly in documentation, tooling (asset management, access control, vulnerability management), training, and consultancy. This can easily match or exceed the assessor fee.
ENX portal registration fees are relatively modest — typically a few hundred euros per scope entry — and are separate from assessor fees.
There is no fixed government fee or regulatory filing cost. TISAX is a private-sector framework. All fees are commercial.
TISAX Anforderungen: Key Requirements Summary
For practitioners tracking specific VDA ISA v6.0 requirements, the framework's primary "must" requirements span:
- Information asset management: all information assets classified according to OEM-aligned classification levels (public, internal, confidential, strictly confidential)
- Access control: need-to-know principle enforced; privileged access reviewed at least annually; multi-factor authentication for remote access and privileged accounts
- Cryptography: data in transit encrypted using current standards; key management procedures documented
- Physical and environmental security: server rooms, print areas, meeting rooms handling sensitive topics all secured and access-logged
- Operations security: vulnerability management programme with defined remediation SLAs; malware protection on all endpoints; logging and monitoring with defined retention
- Incident management: defined classification, escalation, and notification procedure; tested at least annually
- Business continuity: recovery time and recovery point objectives defined and tested for critical systems
- Supplier relationships: security requirements contractually imposed on all suppliers handling in-scope information; periodic review of supplier compliance
- Compliance: legal, regulatory, and contractual obligations inventoried and tracked
For prototype protection (PT label), additional requirements include: camouflage vehicle handling procedures, photography and publication restrictions, visitor management for prototype areas, and non-disclosure agreement processes for external stakeholders.
Maintaining Your TISAX Result
A valid result lasts three years. Maintaining it is not passive:
- Change management: any significant change to the in-scope environment — new locations, new cloud providers, changes to data classification — may require a scope update or a new assessment
- Annual internal reviews: while not formally mandated like ISO 27001 surveillance audits, most competent assessors expect evidence of ongoing ISMS operation, not a snapshot prepared only for the triennial audit
- Corrective actions: findings from the original audit must be tracked to closure; some assessors request evidence of closure before re-assessment
Further Reading
- What is an ISMS? A practitioner's guide
- ISO 27001 certification guide — requirements, timeline, and costs
Frequently Asked Questions
What is TISAX and who needs it? TISAX (Trusted Information Security Assessment Exchange) is an information security assessment framework for the automotive supply chain, managed by the ENX Association using the VDA ISA catalogue. Any supplier handling sensitive information from an OEM — including design data, prototype details, or personal data — will typically be required to hold a valid TISAX assessment result. BMW, Mercedes-Benz, Volkswagen Group, Stellantis, and most major Tier-1 suppliers require it.
Is TISAX the same as ISO 27001 certification? No. TISAX is an assessment that produces a shared result token distributed via the ENX portal. ISO 27001 is an international standard resulting in a formal certificate. The two overlap significantly in control areas but differ in methodology, scope, and how results are shared. Holding ISO 27001 can reduce TISAX audit effort but does not replace it.
What are the TISAX assessment levels? TISAX has three levels: AL1 (plausibility check, self-assessment only), AL2 (on-site audit by an ENX-accredited assessor, the most common OEM requirement), and AL3 (inter-rater audit with additional scrutiny, required for prototype data and highly sensitive information).
What are TISAX labels and what do they mean? TISAX labels describe the scope and sensitivity category assessed. Core label categories are: Information and Data Security (IS, with sub-levels Normal, High, Very High), Prototype Protection (PT and PT-S), and Data Center Hosting (DC). Each label is attached to a specific result and shared only with requesting OEMs via the ENX portal.
How long does TISAX certification take? From kickoff to a valid result: 4 to 6 months for organisations with a mature ISMS, and 12 to 18 months for those starting with limited controls. Registration, assessor scheduling, on-site audit, and finding remediation all consume calendar time.
How much does a TISAX assessment cost? Assessor fees for AL2 audits typically range from roughly $8,000 to $35,000 depending on scope, locations, and label categories. Preparation costs — consultancy, tooling, training — can match or exceed assessor fees for organisations starting from a low baseline.
Do I need TISAX at every company location? Scope must include every location where OEM-relevant information is processed, stored, or transmitted. Excluding a location that handles in-scope data is a common audit finding and can invalidate the result.
What is the VDA ISA and how does it relate to TISAX? The VDA ISA (Information Security Assessment) is the control catalogue that underpins TISAX. Version 6.0 (2024) is the current version. It organises requirements into domains — IS, PT, DC, DP — that ENX-accredited assessors evaluate during the TISAX audit.
Frequently asked questions
What is TISAX and who needs it?
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment framework for the automotive supply chain, managed by the ENX Association using the VDA ISA catalogue. Any supplier handling sensitive information from an OEM — including design data, prototype details, or personal data — will typically be required to hold a valid TISAX assessment result. BMW, Mercedes-Benz, Volkswagen Group, Stellantis, and most major Tier-1 suppliers require it.
Is TISAX the same as ISO 27001 certification?
No. TISAX is an assessment (not a certification) that produces a shared result token distributed via the ENX portal. ISO 27001 is an international standard that results in a formal certificate issued by an accredited certification body. The two overlap significantly in control areas but differ in methodology, scope, and how results are shared. Holding ISO 27001 can reduce TISAX audit effort but does not replace it.
What are the TISAX assessment levels?
TISAX has three assessment levels: AL1 (plausibility check, self-assessment only), AL2 (on-site audit by an ENX-accredited assessor, the most common OEM requirement), and AL3 (inter-rater audit with additional scrutiny, required for prototype data and highly sensitive information). Most supplier agreements specify AL2 as the minimum.
What are TISAX labels and what do they mean?
TISAX labels describe the scope and sensitivity category of the assessment result. The core label categories are: Information and Data Security (IS), Prototype and Vehicle Protection (PT), and Data Center Hosting (DC). Each label is attached to a specific assessment result and shared only with the requesting OEM via the ENX portal, not published publicly.
How long does TISAX certification take?
From project kickoff to a final assessment result, the process typically takes 4 to 18 months. Organizations with a mature information security management system (ISMS) often complete it in 4 to 6 months. Those starting with limited controls in place should plan for 12 to 18 months of preparation before scheduling an audit with an ENX-accredited assessment body.
How much does a TISAX assessment cost?
Assessment body fees for AL2 audits typically range from roughly $8,000 to $35,000 depending on the number of locations in scope, the label categories required, and the assessor. This does not include internal preparation costs such as consultancy, tooling, training, or staff time, which can equal or exceed the assessor fee for organizations starting from a low baseline.
Do I need TISAX at every company location?
The scope depends on where OEM-relevant information is processed, stored, or transmitted. If sensitive project data flows through multiple offices, all relevant locations must be included in the scope. The ENX portal tracks scope by location. Excluding a location that handles in-scope data is one of the most common audit findings.
What is the VDA ISA and how does it relate to TISAX?
The VDA ISA (Verband der Automobilindustrie Information Security Assessment) is the control catalogue that underpins the TISAX methodology. Version 6.0, published in 2024, is the current version. It organizes requirements into domains covering information security, prototype protection, and data center operations. ENX-accredited assessors evaluate supplier controls against VDA ISA requirements during the TISAX audit.
Related reading
EU Cyber Resilience Act (CRA) Explained: Who It Affects and What It Requires
The CRA applies to all products with digital elements sold in the EU. Essential requirements, SBOM mandate, 24-hour vulnerability reporting, and the December 2027 deadline.
complianceWhat Is an ISMS? ISO 27001 Information Security Management System Explained
An ISMS is the documented management system ISO 27001 requires. Clauses 4–10, the 93 Annex A controls, the Statement of Applicability, and how it maps to NIS2 Article 21.
complianceNIS2 Explained: Who Is Affected, What You Must Do, and by When
NIS2 in practice — Annex I and II sectors, size thresholds, essential vs important entities, the ten Article 21 measures, the 24/72-hour reporting cascade, and management liability.
complianceSBOM Explained: Software Bill of Materials, Formats, and Why the CRA Requires One
What an SBOM is, what belongs in one, CycloneDX vs SPDX, how to generate and maintain one, and exactly what the EU Cyber Resilience Act mandates.
Practice this hands-on
Pentevo Academy turns these concepts into guided lessons, videos and quizzes — free.
Start learning free