TISAX · VDA ISA · ENXAutomotive industry

    TISAX: information security for automotive

    Without a valid TISAX label, automotive OEMs and tier suppliers won't put you on the contract. The assessment is based on the VDA ISA catalogue and run by the ENX Association. We get you assessment-ready so you pass first time and sustain that security afterwards.

    Automotive industry

    How TISAX works

    One assessment, recognised across the industry. Verify exact requirements against the current VDA ISA catalogue and the ENX portal.

    • 01

      Who runs it

      TISAX (Trusted Information Security Assessment Exchange) is operated by the ENX Association; criteria derive from the VDA ISA catalogue of the German automotive association.

    • 02

      Who is in scope

      Suppliers, developers and service providers in the automotive supply chain that handle sensitive information from OEMs and their partners.

    • 03

      Assessment levels

      AL1 to AL3. AL1 is self-assessment only (not used in the exchange), AL2 (high protection need) is typically remote and document-based, AL3 (very high protection need) involves an on-site assessment.

    • 04

      Objectives & labels

      Most commonly information security, prototype protection and data protection; the outcome is the corresponding TISAX labels.

    • 05

      Sharing the result

      The result isn't public. You share it selectively with partners via the ENX portal. Validity is typically 3 years.

    • 06

      Not a certification

      TISAX isn't a classic certification but a shared result of an assessment performed by an approved TISAX audit provider.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    TISAX is the automotive industry's information-security assessment mechanism, operated by the ENX Association based on the VDA ISA catalogue. Suppliers and service providers handling sensitive information from carmakers and their partners need it.

    Both rest on information-security management, but TISAX is automotive-specific, uses the VDA ISA catalogue, and its result is shared via the ENX portal. An ISO 27001 ISMS is a strong starting point for a TISAX assessment.

    It depends on the target level (AL2/AL3) and your starting point. After a gap analysis against VDA ISA it's typically weeks to months of implementing controls; we set the schedule around your customer's deadline.

    Yes. Prototype protection is a separate assessment objective with its own physical and logical security requirements. We design and implement the controls and prepare the evidence for the assessment.

    Pass TISAX first time

    We run a gap analysis against the VDA ISA catalogue, implement the missing controls and prepare you for the assessment at your target level.