Definition: TISAX
TISAX (Trusted Information Security Assessment Exchange) is a standardized assessment and labeling scheme for information security in the automotive industry, developed by the German Association of the Automotive Industry (VDA) and operated by the ENX Association.
Core characteristics of TISAX
TISAX translates general information security practice into a shared framework that OEMs, Tier-1, and Tier-2 suppliers all recognize, so a supplier is assessed once and shares the result with multiple customers through a central exchange.
- Based on the VDA Information Security Assessment (ISA) catalog
- Results are exchanged through the ENX portal instead of one-off customer audits
- Scope and assessment level depend on the sensitivity of data or prototypes handled
- Labels cover specific locations and assessment objectives, not the whole company by default
TISAX vs. ISO 27001
TISAX and ISO 27001 both assess information security management, but they serve different purposes. ISO 27001 certifies a general information security management system (ISMS) against an international standard, while TISAX is an automotive-specific assessment built on VDA ISA controls that are themselves aligned with ISO 27001 and ISO 27002. A company with an existing ISO 27001 certification can reuse much of that groundwork, but the two are not interchangeable: TISAX results are exchanged only through the ENX portal, while ISO 27001 certificates are recognized across all industries. Some Mittelstand suppliers instead build their ISMS on BSI IT-Grundschutz, Germany’s national framework, before layering VDA ISA controls on top.
Importance of TISAX in enterprise AI
For automotive suppliers, TISAX has moved from a competitive advantage to a de facto entry ticket. More than 20,000 locations worldwide now hold a valid TISAX label, and OEMs increasingly write it into supplier contracts as a precondition rather than a preference. As suppliers connect AI tools to engineering data, assessors increasingly probe how those tools are governed, making documented AI vendor risk management part of a clean assessment.
Methods and procedures for TISAX
TISAX assessment follows a structured path defined by VDA ISA and administered through the ENX portal.
Selecting the assessment level and scope
Before starting, a supplier’s OEM or Tier-1 customer specifies which assessment level and scope objectives apply, based on the sensitivity of the data or prototypes the supplier will handle.
- Level 1: self-assessment questionnaire only, no external audit
- Level 2: self-assessment plus a plausibility check, often a phone review, by an approved provider
- Level 3: full on-site audit with interviews and evidence review for highly sensitive data or prototype protection
Working through the VDA ISA questionnaire
The supplier completes the VDA ISA controls catalog, covering information security, prototype protection, and data protection modules, and closes gaps against the current control version before the formal AI audit-style provider assessment begins.
Publishing the label through the ENX portal
Once an ENX-approved provider confirms the result, the label is published on the ENX portal, where the supplier shares it with multiple OEM and Tier-1 customers instead of repeating the process for each one.
Important KPIs for TISAX
Suppliers track a small set of indicators to keep a TISAX label current and useful.
Assessment and renewal metrics
- Label validity remaining: renewal initiated at least 6 months before expiry
- Scope coverage: share of relevant locations and systems included in the label
- Control implementation rate: share of VDA ISA controls with documented evidence
- Open findings closure time: days to remediate audit findings
Strategic supplier relationship metrics
A valid label increasingly functions as a qualification gate in OEM sourcing rather than a bonus point. Suppliers without a current label report longer sales cycles and, in some cases, exclusion from RFPs involving prototype or connected-vehicle data.
Assessment quality indicators
Assessors look for evidence that controls operate in daily practice, not only on paper. Repeated major findings across renewal cycles are a useful internal signal that the ISMS is not maturing between assessments.
Risk factors and controls for TISAX
TISAX projects carry risks that go beyond passing the initial assessment.
Wrong scope or assessment level
Choosing too narrow a scope or too low an assessment level based on outdated customer requirements can force a costly re-scope mid-project.
- Confirm the required level and scope directly with the requesting OEM or Tier-1 customer
- Reconfirm requirements at each contract renewal, since customer requirements evolve
- Document scope decisions to defend them during the audit
Treating TISAX as a one-time project
Some suppliers prepare intensively for the audit and then let controls lapse until the next renewal cycle. This creates a harder, more expensive reassessment three years later, especially where new AI tools or vendors were added without going through change control.
Data protection and third-party exposure
TISAX assessments increasingly examine how personal and confidential data flows to subcontractors and software vendors, including AI tools. Suppliers processing personal data in engineering or quality workflows should coordinate preparation with their Data Protection Officer to avoid gaps against GDPR.
Practical example
A 180-employee precision parts manufacturer in Baden-Württemberg supplying transmission components to two German OEMs needed a Level 2 TISAX label to keep an existing framework agreement. Security responsibilities had been informally split between IT and quality management, with no documented ISMS. The company ran a twelve-week preparation covering the VDA ISA questionnaire, prototype protection for its testing lab, and CAD access controls. The Level 2 plausibility check passed with two minor findings, both closed within four weeks.
- Documented information security policy approved by management
- Access control matrix covering CAD and PLM systems handling OEM data
- Prototype protection procedures for the physical testing lab
- Supplier questionnaire process extended to its own subcontractors
Current developments and effects
TISAX continues to evolve alongside broader EU cybersecurity regulation.
VDA ISA moves to an annual release cycle
VDA ISA2027 was published in mid-2026 and becomes mandatory from January 2027, replacing the multi-year update cycle used for ISA 6.
- Annual updates require suppliers to track control changes more actively
- Existing labels remain valid under their original catalog version until renewal
- Assessment providers must requalify against each new catalog version
Overlap with NIS2 and the Cyber Resilience Act
As Germany’s NIS2 implementation and the EU’s Cyber Resilience Act extend cybersecurity obligations across the supply chain, suppliers increasingly reuse TISAX control evidence for these obligations rather than building parallel documentation.
AI tools entering the assessment scope
As suppliers connect AI copilots and agents to engineering and quality systems, assessors are starting to ask how those tools are governed and where data flows, pushing information security and AI governance planning together earlier in projects.
Conclusion
TISAX has become the practical price of entry for doing business with German OEMs and their Tier-1 suppliers, even though no law requires it. Suppliers that treat the assessment as a living security program rather than a one-time audit event pass renewals with fewer findings and lower cost over time. As VDA ISA moves to annual updates and AI tools enter supplier environments, the assessment scope will keep expanding. Mittelstand suppliers that build TISAX readiness into standard operating procedure now avoid the scramble of a surprise scope change or sudden reassessment deadline.
Frequently Asked Questions
What is TISAX and who requires it?
TISAX is an information security assessment standard for the automotive industry, developed by the VDA and administered by ENX. German OEMs and Tier-1 suppliers require it from suppliers handling confidential data, prototypes, or connected-vehicle information, even though it is not a legal requirement.
What is the difference between TISAX assessment levels?
Level 1 requires only a self-assessment questionnaire. Level 2 adds a plausibility check, typically by phone, from an approved provider. Level 3 requires a full on-site audit, reserved for the most sensitive data and prototype protection cases.
What does a TISAX assessment cost for a mid-sized supplier?
External auditor fees for German SMEs typically run 4,000 to 8,000 euros depending on level. Including internal preparation and consulting support, total first-year project costs commonly reach 15,000 to 51,000 euros.
How is TISAX different from ISO 27001?
ISO 27001 certifies a general information security management system recognized across industries. TISAX is an automotive-specific assessment based on the VDA ISA catalog, itself aligned with ISO 27001 controls, and results are exchanged only through the ENX portal.
How long does TISAX preparation take and how long is the label valid?
A first-time Level 2 assessment typically takes two to four months of preparation, depending on how mature existing security practices are. A label is valid for three years, after which the supplier must complete a reassessment.
Is there funding available for TISAX preparation in the German Mittelstand?
Some German states offer digitalization and cybersecurity funding programs that cover part of the consulting cost for information security projects, though TISAX-specific funding lines are rare. Suppliers should check current regional programs, since availability changes frequently.