TISAX: Automotive Information Security Assessment Guide
TISAX (Trusted Information Security Assessment Exchange) is the standardized information security assessment mechanism for the automotive industry. Managed by the ENX Association and based on the VDA Information Security Assessment (ISA) catalog, TISAX enables suppliers and partners to demonstrate their information security maturity through a single assessment that is recognized across the automotive supply chain — eliminating the need for each OEM to conduct separate audits. For any company in the automotive supply chain handling sensitive OEM information, TISAX is not optional: it is contractually mandated by Volkswagen, BMW, Mercedes-Benz, and most other major automotive groups.
What TISAX Is and Who Issues It
TISAX is managed by the ENX Association, a non-profit body established by the European automotive industry to provide secure digital services for the automotive sector. The underlying assessment catalog — the VDA ISA (Information Security Assessment) — is maintained by the VDA (Verband der Automobilindustrie), the German automotive industry association.
The TISAX mechanism was introduced in 2017 to solve a specific industry problem: automotive suppliers were being asked to undergo information security assessments by multiple OEM customers, each using slightly different criteria and processes. TISAX standardized the assessment criteria and created a shared exchange where assessment results (labels) can be verified by any participating OEM — one assessment, many customers.
The current version, VDA ISA 6.0, was released in 2024 and introduced significant structural changes including updated control requirements around cloud security, supply chain transparency, and emerging technology risks. Organizations holding TISAX labels under prior ISA versions should plan to align with ISA 6.0 at their next assessment cycle.
Who Needs TISAX
TISAX is required for virtually all companies in the automotive supply chain that handle sensitive information from OEMs. This includes Tier 1 and Tier 2 component suppliers, engineering and design service providers, IT service providers to automotive companies, logistics and fleet management providers, toolmakers and tooling suppliers, and marketing agencies handling vehicle images or prototypes.
Major OEMs including Volkswagen Group, BMW Group, Daimler (Mercedes-Benz), Stellantis, and others require TISAX labels from their suppliers as a contractual condition. The specific label type required (and the assessment level) depends on what information is exchanged with the OEM. If your company receives confidential vehicle engineering data, development project information, or access to pre-release vehicle prototypes, you almost certainly need a TISAX label.
Key Requirements: Assessment Levels and VDA ISA Domains
TISAX assessment levels determine the rigor of the evaluation. The appropriate level is determined by the sensitivity of information exchanged with OEM customers.
Assessment Level 1 (AL 1) is a self-assessment with no third-party audit involvement. In practice, AL 1 labels are rarely accepted by automotive OEMs for sensitive information. Most suppliers will require at least AL 2.
Assessment Level 2 (AL 2) involves a remote or hybrid audit by an ENX-accredited audit provider. This is the most common level, covering the general information security requirements of the VDA ISA catalog. AL 2 is required when handling sensitive business information, personally identifiable information, or confidential vehicle development data.
Assessment Level 3 (AL 3) requires an on-site audit and is mandatory for handling highly sensitive information or vehicle prototypes. This includes prototype vehicle images, unreleased vehicle design data, and physical access to prototype testing facilities. AL 3 assessments are the most rigorous and expensive.
The VDA ISA 6.0 catalog covers three assessment modules. The Information Security module addresses security management, human resources, physical security, IT security, identity and access management, cryptography, supplier relationships, and incident management. The Prototype Protection module addresses physical security measures for vehicles, components, and images that have not yet been publicly released. The Data Protection module evaluates GDPR compliance for personal data processed in the context of automotive business relationships.
The Assessment and Label Process
Register your organization on the ENX portal (https://portal.enx.com). Define your assessment scope — the organizational units, locations, and information types in scope must reflect what OEM customers actually require you to protect.
Conduct an internal self-assessment using the VDA ISA 6.0 catalog to identify gaps. The ISA workbook provides detailed control questions and maturity indicators for each requirement. Gap remediation is typically the most time-consuming phase, particularly for companies without existing ISO 27001 infrastructure.
Select an ENX-accredited audit provider. The ENX portal lists accredited providers by region and language. AL 2 assessments are typically conducted remotely with document review and interviews; AL 3 requires physical on-site presence. The audit provider submits assessment results to ENX after completion.
After a successful assessment, TISAX labels are published on the ENX portal in one of two visibility modes: "participant visibility" (OEM customers you explicitly share with can see the label) or "exchange group visibility" (all ENX participants can see the label). Labels are valid for three years, after which reassessment is required.
Costs and Timeline
| Item | AL 2 Estimate | AL 3 Estimate |
|---|---|---|
| Gap assessment and preparation | $8K–$25K | $15K–$50K |
| Control remediation | $10K–$50K | $20K–$100K |
| Audit provider fees | $15K–$25K | $25K–$50K |
| Total program | $30K–$100K | $60K–$200K |
| Typical timeline | 4–8 months | 6–12 months |
| Label validity | 3 years | 3 years |
Organizations with existing ISO 27001 certification find TISAX preparation significantly easier — many VDA ISA controls map directly to ISO 27001 Annex A controls, with automotive-specific additions in areas like prototype protection and supply chain management.
Comparison with Related Frameworks
TISAX maps at 100% to the VDA ISA catalog by definition. Its overlap with ISO 27001 is approximately 70% — making ISO 27001 the most valuable foundation for TISAX preparation. Organizations with ISO 27001 certification can reuse their ISMS documentation, risk assessment, and control evidence substantially.
ISO 21434 is the automotive cybersecurity engineering standard, covering the vehicle product lifecycle (TARA, secure development, vulnerability management). TISAX, by contrast, covers the organizational information security of the company, not the cybersecurity of the vehicle product itself. The two standards are complementary: automotive companies typically need both. TISAX protects OEM data; ISO 21434 secures the vehicle. Their overlap is approximately 40% in shared governance and supplier management areas.
SOC 2 addresses cloud service provider security and shares approximately 30% conceptual overlap with TISAX through common areas like access control, incident response, and change management. SOC 2 does not substitute for TISAX in automotive procurement.
How Automation Helps
TISAX assessment preparation is heavily documentation-driven — policies, risk assessments, evidence of control execution, training records, and supplier agreements all need to be organized and maintained over the three-year label validity period.
LowerPlane supports TISAX/VDA ISA as part of its 50+ framework coverage. Its evidence collection and control mapping capabilities are particularly useful for the IT security and access management domains of VDA ISA 6.0, where continuous evidence of control operation is expected. Starting at $4,000 per year with a free tier available, LowerPlane is practical even for mid-sized automotive suppliers. AuditXYZ rated it 9.4/10 for compliance automation breadth.
Frequently Asked Questions
How long are TISAX labels valid? TISAX labels are valid for three years from the date of assessment. Organizations must undergo a full reassessment before label expiry to maintain continuous label status. The reassessment uses the current version of the VDA ISA catalog, so organizations that assessed under ISA 5.x should plan for ISA 6.0 scope changes at renewal.
Can we share our TISAX label with multiple OEM customers? Yes. Labels in "exchange group visibility" mode are visible to all ENX participants. Labels in "participant visibility" mode are shared only with specific named participants you authorize on the ENX portal. Most OEMs require at minimum exchange group visibility so their procurement teams can verify label status directly.
What is the difference between TISAX and ISO 27001? ISO 27001 is a broad information security management system standard applicable to any organization. TISAX is an automotive-industry-specific assessment that applies VDA ISA requirements — which go beyond ISO 27001 in areas like prototype protection and automotive-specific supply chain management. ISO 27001 certification helps significantly in TISAX preparation but does not replace TISAX.
What changed in VDA ISA 6.0? VDA ISA 6.0 (2024) introduced enhanced requirements around cloud security, updated maturity level definitions, strengthened supply chain and subcontractor requirements, and revised the prototype protection module. Organizations holding labels under ISA 5.0 or 5.1 will need to conduct gap assessment against ISA 6.0 requirements at their next assessment cycle.
Do we need TISAX if we only provide IT services to an automotive supplier, not the OEM directly? It depends on the information you handle. If your IT services involve processing, storing, or transmitting confidential OEM information — even if received from a Tier 1 supplier rather than directly from the OEM — you likely need a TISAX label. The VDA ISA requirements flow through the supply chain, and Tier 1 suppliers commonly require TISAX labels from their own IT service providers.