What is TISAX? A guide to TISAX certification
Looking to understand the TISAX label and why TISAX certification is a key standard for the automotive sector? Read this guide.
Updated September 1, 2026:quality(90))
TISAX (Trusted Information Security Assessment Exchange) is the information security standard for the automotive supply chain. If your organization handles sensitive data and wants to work with German automotive OEMs, you need it.
This guide covers what TISAX requires, who needs it, how certification works, and how to achieve the label.
TISAX is a standardized information security assessment and certification framework built specifically for the automotive sector. The standard stems from the German Association of the Automotive Industry (VDA) Information Security Assessment (ISA) questionnaire. It largely follows the international ISO/IEC 27001 standard.
Achieving the TISAX label lets your organization share a standardized security assessment with partners, customers, and regulators across the automotive supply chain. This removes the need to run separate audits for each one.
The ENX Association operates the TISAX program and defines assessment levels and scope.
A group of European (mostly German) auto manufacturers created the standard in 2016. In April 2024, it was updated to improve ransomware resilience controls and better address IT/OT convergence security. In July 2026, ISA2027 was published and will be effective in January 2027.
The updates in ISA2027 are designed for:
Better clarity
More consistency
Stronger focus on supply chain security
Restructured prototype protection
The ENX TISAX platform gives registered organizations a practical advantage:
One audit, many partners: Audit results are yours to share (or not) with anyone on the platform. No need to repeat assessments for every new partner relationship.
Stronger supplier security: Verify that suppliers and service providers meet baseline data protection and information security requirements before you work together.
Built-in security awareness: The self-assessment process drives security awareness internally across your organization.
A path to ISO 27001: TISAX lays the groundwork for a full information security management system (ISMS) and potential ISO 27001 certification.
Three areas drive TISAX compliance:
Information security: You need a working Information Security Management System (ISMS). One that identifies and manages risks, establishes security policies and procedures, and undergoes regular audits.
Prototype protection: Physical prototypes (vehicles, parts, and components) must be secured against unauthorized exposure.
Data Protection: Sensitive data must meet standards for confidentiality, integrity, and availability. That means access controls, encryption, secure storage, and employee training.
The TISAX participant handbook has the full overview of the label process.
Any company working with the German automotive industry needs the TISAX label. That now covers manufacturers, suppliers, and service providers across the global German automotive supply chain. In practice, TISAX has become the baseline requirement for working with any OEM.
Andre Froneman, OT solutions specialist at Datacentrix in South Africa, sees this firsthand:
"I'm located in what you might call the Detroit of South Africa, a manufacturing hub for Mercedes Benz, Volkswagen, Ford, and Isuzu, as well as auto parts manufacturers that are part of German automakers' supply chain. The challenge we see with TISAX compliance is getting the visibility needed across their OT and IT networks to complete self-assessments, and evaluating where the TISAX auditors will want to see security, specifically for their environment."
Budget for three things:
Audit provider fee: Typically 5,000 to 10,000 euros, depending on company size and scope.
Registration fee: Approximately 500 euros (mandatory)
Operational costs: Preparing for the audit and implementing or configuring an ISMS
The TISAX label is valid for three years.
TISAX compliance results in a label, not a certificate (unlike ISO 27001). The process has three stages:
Register your organization as a participant on the ENX platform
Assess your readiness with a self-assessment, then work with an accredited TISAX audit provider for the formal assessment.
Share your assessment results with partners via the ENX platform on your terms.
The VDA recommends starting with the “Information security assessment (ISA)” questionnaire as a self-assessment. It covers eight security areas:
Information security policies and organization
Human Resources
Physical security and business continuity
IT security/cyber security
Supplier relationships
Compliance
Prototype protection
Each area gets a rating from 0 to 5. The ISA spider chart maps those ratings to maturity levels across all security topics.

Image source: VDA Information Security Assessment
To receive the TISAX label, your organization must reach maturity level 3. Self-assessing before your formal audit is worth doing so you can close gaps before they become audit findings.
Maturity level | In one word | Description |
|---|---|---|
0 | Incomplete | A process is not available, not followed or not suitable for achieving the objective. |
1 | Performed | An undocumented or incompletely documented process is followed and indicators exist that it achieves its objective. |
2 | Managed | A process achieving its objectives is followed. Process documentation and process implementation evidence are available. |
3 | Established | A standard process integrated into the overall system is followed. Dependencies on other processes are documented and suitable interfaces are created. Evidence exists that the process has been used sustainably and actively over an extended period. |
4 | Predictable | An established process is followed. The effectiveness of the process is continually monitored by collecting key figures. Limit values are defined at which the process is considered to be insufficiently effective and requires adjustment. (Key Performance Indicators) |
5 | Optimizing | A predictable process with continual improvement as a major objective is followed. Improvement is actively advanced by dedicated resources. |
Source: TISAX Participant Handbook, Table 11
TISAX targets the automotive industry specifically. Here's what sets it apart.
Shared assessments via the ENX platform: Organizations can look up suppliers' TISAX status and share their own. Get one audit instead of one for each new partner.
Risk-based approach: TISAX uses a risk-based method that evaluates the full vehicle system. This includes hardware, software, and communication protocols. It mandates compliance with the VDA standard, including requirements for a cybersecurity management system.
Industry-specific scope: ISO 27001 covers all industries. TISAX applies specifically to the needs and risks of the automotive supply chain.
Many compare TISAX with ISO 27001, and with good reason. Both are information security standards with significant overlap: approximately 90% of TISAX controls derive from the ISO 27001 Annex A framework. That said, the scope and application differ.
TISAX | ISO 27001 | |
|---|---|---|
Regulatory scope | VDA, which is mainly German | International |
Industry focus | Automotive | All industries |
Data protected | Manufacturer data throughout supply chain | Company data or data entrusted to the company |
Requirements | There are 6 levels (0-5), label received after completion of level 3 | Each of the 114 controls as well as Annex A must be addressed to receive certification |
Application perimeter | Entire site, no exclusions | Allows precise perimeter to be defined |
Method of evaluation | Assessment-based | Audit-based |
Proof | Electronic label (only available on ENX platform) | Certificate |
Audit frequency | Every 3 years | Yearly |
Source: IS Decisions
Run regular risk assessments: Identify potential risks and vulnerabilities in your information security landscape. Implement controls, then regularly review and update them. Risk assessments only work if they stay current.
Build a strong security culture: TISAX training is most effective when it's ongoing, not a one-time checkbox. Employees need to understand their role in keeping data secure throughout the supply chain.
Enforce access controls: Limit access to sensitive data to authorized personnel only. Multi-factor authentication (MFA), strong password policies, and role-based access controls significantly lower the risk of unauthorized access.
Work with accredited TISAX auditors: Find providers with specific TISAX experience. They can surface gaps before the formal assessment and make the process more efficient.
UserLock and FileAudit directly address TISAX's Identity and Access Management and IT Security controls, two of the highest-scrutiny areas in the assessment. These are also among the hardest to achieve with TISAX compliance software in on-premises and hybrid Active Directory environments.
See exactly how they map to specific TISAX requirements in our TISAX compliance checklist.
:quality(90))
:quality(90))
:quality(90))