What is TISAX? A guide to TISAX certification

Looking to understand the TISAX label and why TISAX certification is a key standard for the automotive sector? Read this guide.

Updated September 1, 2026
Tisax compliance

TISAX (Trusted Information Security Assessment Exchange) is the information security standard for the automotive supply chain. If your organization handles sensitive data and wants to work with German automotive OEMs, you need it.

This guide covers what TISAX requires, who needs it, how certification works, and how to achieve the label.

What is TISAX certification?

TISAX is a standardized information security assessment and certification framework built specifically for the automotive sector. The standard stems from the German Association of the Automotive Industry (VDA) Information Security Assessment (ISA) questionnaire. It largely follows the international ISO/IEC 27001 standard.

Achieving the TISAX label lets your organization share a standardized security assessment with partners, customers, and regulators across the automotive supply chain. This removes the need to run separate audits for each one.

The ENX Association operates the TISAX program and defines assessment levels and scope.

A group of European (mostly German) auto manufacturers created the standard in 2016. In April 2024, it was updated to improve ransomware resilience controls and better address IT/OT convergence security. In July 2026, ISA2027 was published and will be effective in January 2027.

What's new in ISA2027?

The updates in ISA2027 are designed for:

  • Better clarity

  • More consistency

  • Stronger focus on supply chain security

  • Restructured prototype protection

What are the benefits of TISAX?

The ENX TISAX platform gives registered organizations a practical advantage:

  • One audit, many partners: Audit results are yours to share (or not) with anyone on the platform. No need to repeat assessments for every new partner relationship.

  • Stronger supplier security: Verify that suppliers and service providers meet baseline data protection and information security requirements before you work together.

  • Built-in security awareness: The self-assessment process drives security awareness internally across your organization.

  • A path to ISO 27001: TISAX lays the groundwork for a full information security management system (ISMS) and potential ISO 27001 certification.

What are TISAX requirements?

Three areas drive TISAX compliance:

  • Information security: You need a working Information Security Management System (ISMS). One that identifies and manages risks, establishes security policies and procedures, and undergoes regular audits.

  • Prototype protection: Physical prototypes (vehicles, parts, and components) must be secured against unauthorized exposure.

  • Data Protection: Sensitive data must meet standards for confidentiality, integrity, and availability. That means access controls, encryption, secure storage, and employee training.

The TISAX participant handbook has the full overview of the label process.

Who needs TISAX certification?

Any company working with the German automotive industry needs the TISAX label. That now covers manufacturers, suppliers, and service providers across the global German automotive supply chain. In practice, TISAX has become the baseline requirement for working with any OEM.

Andre Froneman, OT solutions specialist at Datacentrix in South Africa, sees this firsthand:

"I'm located in what you might call the Detroit of South Africa, a manufacturing hub for Mercedes Benz, Volkswagen, Ford, and Isuzu, as well as auto parts manufacturers that are part of German automakers' supply chain. The challenge we see with TISAX compliance is getting the visibility needed across their OT and IT networks to complete self-assessments, and evaluating where the TISAX auditors will want to see security, specifically for their environment."

How much does TISAX cost?

Budget for three things:

  • Audit provider fee: Typically 5,000 to 10,000 euros, depending on company size and scope.

  • Registration fee: Approximately 500 euros (mandatory)

  • Operational costs: Preparing for the audit and implementing or configuring an ISMS

How long does TISAX last?

The TISAX label is valid for three years.

TISAX compliance: How does the TISAX certification process work?

TISAX compliance results in a label, not a certificate (unlike ISO 27001). The process has three stages:

  1. Register your organization as a participant on the ENX platform

  2. Assess your readiness with a self-assessment, then work with an accredited TISAX audit provider for the formal assessment.

  3. Share your assessment results with partners via the ENX platform on your terms.

Understand the TISAX control categories

The VDA recommends starting with the “Information security assessment (ISA)” questionnaire as a self-assessment. It covers eight security areas:

  1. Information security policies and organization

  2. Human Resources

  3. Physical security and business continuity

  4. Identity and access management

  5. IT security/cyber security

  6. Supplier relationships

  7. Compliance

  8. Prototype protection

Each area gets a rating from 0 to 5. The ISA spider chart maps those ratings to maturity levels across all security topics.

TISAX VDA information security assessment

Image source: VDA Information Security Assessment

What are the TISAX maturity levels?

To receive the TISAX label, your organization must reach maturity level 3. Self-assessing before your formal audit is worth doing so you can close gaps before they become audit findings.

Maturity level

In one word

Description

0

Incomplete

A process is not available, not followed or not suitable for achieving the objective.

1

Performed

An undocumented or incompletely documented process is followed and indicators exist that it achieves its objective.

2

Managed

A process achieving its objectives is followed. Process documentation and process implementation evidence are available.

3

Established

A standard process integrated into the overall system is followed. Dependencies on other processes are documented and suitable interfaces are created. Evidence exists that the process has been used sustainably and actively over an extended period.

4

Predictable

An established process is followed. The effectiveness of the process is continually monitored by collecting key figures. Limit values are defined at which the process is considered to be insufficiently effective and requires adjustment. (Key Performance Indicators)

5

Optimizing

A predictable process with continual improvement as a major objective is followed. Improvement is actively advanced by dedicated resources.

Source: TISAX Participant Handbook, Table 11

How is the TISAX label different from other cybersecurity certifications?

TISAX targets the automotive industry specifically. Here's what sets it apart.

  • Shared assessments via the ENX platform: Organizations can look up suppliers' TISAX status and share their own. Get one audit instead of one for each new partner.

  • Risk-based approach: TISAX uses a risk-based method that evaluates the full vehicle system. This includes hardware, software, and communication protocols. It mandates compliance with the VDA standard, including requirements for a cybersecurity management system.

  • Industry-specific scope: ISO 27001 covers all industries. TISAX applies specifically to the needs and risks of the automotive supply chain.

What is the difference between TISAX and ISO 27001?

Many compare TISAX with ISO 27001, and with good reason. Both are information security standards with significant overlap: approximately 90% of TISAX controls derive from the ISO 27001 Annex A framework. That said, the scope and application differ.

TISAX

ISO 27001

Regulatory scope

VDA, which is mainly German

International

Industry focus

Automotive

All industries

Data protected

Manufacturer data throughout supply chain

Company data or data entrusted to the company

Requirements

There are 6 levels (0-5), label received after completion of level 3

Each of the 114 controls as well as Annex A must be addressed to receive certification

Application perimeter

Entire site, no exclusions

Allows precise perimeter to be defined

Method of evaluation

Assessment-based

Audit-based

Proof

Electronic label (only available on ENX platform)

Certificate

Audit frequency

Every 3 years

Yearly

Source: IS Decisions

Best practices for achieving the TISAX label

  • Run regular risk assessments: Identify potential risks and vulnerabilities in your information security landscape. Implement controls, then regularly review and update them. Risk assessments only work if they stay current.

  • Build a strong security culture: TISAX training is most effective when it's ongoing, not a one-time checkbox. Employees need to understand their role in keeping data secure throughout the supply chain.

  • Enforce access controls: Limit access to sensitive data to authorized personnel only. Multi-factor authentication (MFA), strong password policies, and role-based access controls significantly lower the risk of unauthorized access.

  • Work with accredited TISAX auditors: Find providers with specific TISAX experience. They can surface gaps before the formal assessment and make the process more efficient.

How IS Decisions supports TISAX certification

UserLock and FileAudit directly address TISAX's Identity and Access Management and IT Security controls, two of the highest-scrutiny areas in the assessment. These are also among the hardest to achieve with TISAX compliance software in on-premises and hybrid Active Directory environments.

See exactly how they map to specific TISAX requirements in our TISAX compliance checklist.

XFacebookLinkedIn

francois-amigorena-headshot

François Amigorena

President and CEO, IS Decisions

François Amigorena is the founder of IS Decisions, a global software company specializing in access management and MFA for Microsoft Windows and Active Directory. He is a frequently published author on topics like Zero Trust architecture, insider threats, password policies, and user security awareness.