AI Guide

TISAX: The information security standard automotive suppliers cannot ignore

TISAX (Trusted Information Security Assessment Exchange) is the information security assessment standard that German OEMs and Tier-1 suppliers require from their automotive supply chain. Established by the German Association of the Automotive Industry (VDA) and administered by ENX, it evaluates how companies protect confidential prototypes, engineering data, and personal information shared across the supply chain. Learn below what TISAX requires, how the three assessment levels work, and what certification realistically costs a mid-sized supplier.

Key Facts
  • TISAX has three assessment levels, from a self-assessment questionnaire (Level 1) to a full on-site audit (Level 3).
  • More than 20,000 TISAX-assessed locations worldwide held a valid label as of late 2025, according to ENX Association.
  • External auditor fees for German SMEs typically range from 4,000 to 8,000 euros, with total project costs reaching 15,000 to 51,000 euros.
  • TISAX labels are valid for three years and must be renewed through a reassessment.
  • TISAX is not a legal requirement, but many OEMs and Tier-1 suppliers will not award or renew contracts without a valid label.

Definition: TISAX

TISAX (Trusted Information Security Assessment Exchange) is a standardized assessment and labeling scheme for information security in the automotive industry, developed by the German Association of the Automotive Industry (VDA) and operated by the ENX Association.

Core characteristics of TISAX

TISAX translates general information security practice into a shared framework that OEMs, Tier-1, and Tier-2 suppliers all recognize, so a supplier is assessed once and shares the result with multiple customers through a central exchange.

  • Based on the VDA Information Security Assessment (ISA) catalog
  • Results are exchanged through the ENX portal instead of one-off customer audits
  • Scope and assessment level depend on the sensitivity of data or prototypes handled
  • Labels cover specific locations and assessment objectives, not the whole company by default

TISAX vs. ISO 27001

TISAX and ISO 27001 both assess information security management, but they serve different purposes. ISO 27001 certifies a general information security management system (ISMS) against an international standard, while TISAX is an automotive-specific assessment built on VDA ISA controls that are themselves aligned with ISO 27001 and ISO 27002. A company with an existing ISO 27001 certification can reuse much of that groundwork, but the two are not interchangeable: TISAX results are exchanged only through the ENX portal, while ISO 27001 certificates are recognized across all industries. Some Mittelstand suppliers instead build their ISMS on BSI IT-Grundschutz, Germany’s national framework, before layering VDA ISA controls on top.

Importance of TISAX in enterprise AI

For automotive suppliers, TISAX has moved from a competitive advantage to a de facto entry ticket. More than 20,000 locations worldwide now hold a valid TISAX label, and OEMs increasingly write it into supplier contracts as a precondition rather than a preference. As suppliers connect AI tools to engineering data, assessors increasingly probe how those tools are governed, making documented AI vendor risk management part of a clean assessment.

Methods and procedures for TISAX

TISAX assessment follows a structured path defined by VDA ISA and administered through the ENX portal.

Selecting the assessment level and scope

Before starting, a supplier’s OEM or Tier-1 customer specifies which assessment level and scope objectives apply, based on the sensitivity of the data or prototypes the supplier will handle.

  • Level 1: self-assessment questionnaire only, no external audit
  • Level 2: self-assessment plus a plausibility check, often a phone review, by an approved provider
  • Level 3: full on-site audit with interviews and evidence review for highly sensitive data or prototype protection

Working through the VDA ISA questionnaire

The supplier completes the VDA ISA controls catalog, covering information security, prototype protection, and data protection modules, and closes gaps against the current control version before the formal AI audit-style provider assessment begins.

Publishing the label through the ENX portal

Once an ENX-approved provider confirms the result, the label is published on the ENX portal, where the supplier shares it with multiple OEM and Tier-1 customers instead of repeating the process for each one.

Important KPIs for TISAX

Suppliers track a small set of indicators to keep a TISAX label current and useful.

Assessment and renewal metrics

  • Label validity remaining: renewal initiated at least 6 months before expiry
  • Scope coverage: share of relevant locations and systems included in the label
  • Control implementation rate: share of VDA ISA controls with documented evidence
  • Open findings closure time: days to remediate audit findings

Strategic supplier relationship metrics

A valid label increasingly functions as a qualification gate in OEM sourcing rather than a bonus point. Suppliers without a current label report longer sales cycles and, in some cases, exclusion from RFPs involving prototype or connected-vehicle data.

Assessment quality indicators

Assessors look for evidence that controls operate in daily practice, not only on paper. Repeated major findings across renewal cycles are a useful internal signal that the ISMS is not maturing between assessments.

Risk factors and controls for TISAX

TISAX projects carry risks that go beyond passing the initial assessment.

Wrong scope or assessment level

Choosing too narrow a scope or too low an assessment level based on outdated customer requirements can force a costly re-scope mid-project.

  • Confirm the required level and scope directly with the requesting OEM or Tier-1 customer
  • Reconfirm requirements at each contract renewal, since customer requirements evolve
  • Document scope decisions to defend them during the audit

Treating TISAX as a one-time project

Some suppliers prepare intensively for the audit and then let controls lapse until the next renewal cycle. This creates a harder, more expensive reassessment three years later, especially where new AI tools or vendors were added without going through change control.

Data protection and third-party exposure

TISAX assessments increasingly examine how personal and confidential data flows to subcontractors and software vendors, including AI tools. Suppliers processing personal data in engineering or quality workflows should coordinate preparation with their Data Protection Officer to avoid gaps against GDPR.

Practical example

A 180-employee precision parts manufacturer in Baden-Württemberg supplying transmission components to two German OEMs needed a Level 2 TISAX label to keep an existing framework agreement. Security responsibilities had been informally split between IT and quality management, with no documented ISMS. The company ran a twelve-week preparation covering the VDA ISA questionnaire, prototype protection for its testing lab, and CAD access controls. The Level 2 plausibility check passed with two minor findings, both closed within four weeks.

  • Documented information security policy approved by management
  • Access control matrix covering CAD and PLM systems handling OEM data
  • Prototype protection procedures for the physical testing lab
  • Supplier questionnaire process extended to its own subcontractors

Current developments and effects

TISAX continues to evolve alongside broader EU cybersecurity regulation.

VDA ISA moves to an annual release cycle

VDA ISA2027 was published in mid-2026 and becomes mandatory from January 2027, replacing the multi-year update cycle used for ISA 6.

  • Annual updates require suppliers to track control changes more actively
  • Existing labels remain valid under their original catalog version until renewal
  • Assessment providers must requalify against each new catalog version

Overlap with NIS2 and the Cyber Resilience Act

As Germany’s NIS2 implementation and the EU’s Cyber Resilience Act extend cybersecurity obligations across the supply chain, suppliers increasingly reuse TISAX control evidence for these obligations rather than building parallel documentation.

AI tools entering the assessment scope

As suppliers connect AI copilots and agents to engineering and quality systems, assessors are starting to ask how those tools are governed and where data flows, pushing information security and AI governance planning together earlier in projects.

Conclusion

TISAX has become the practical price of entry for doing business with German OEMs and their Tier-1 suppliers, even though no law requires it. Suppliers that treat the assessment as a living security program rather than a one-time audit event pass renewals with fewer findings and lower cost over time. As VDA ISA moves to annual updates and AI tools enter supplier environments, the assessment scope will keep expanding. Mittelstand suppliers that build TISAX readiness into standard operating procedure now avoid the scramble of a surprise scope change or sudden reassessment deadline.

Frequently Asked Questions

What is TISAX and who requires it?

TISAX is an information security assessment standard for the automotive industry, developed by the VDA and administered by ENX. German OEMs and Tier-1 suppliers require it from suppliers handling confidential data, prototypes, or connected-vehicle information, even though it is not a legal requirement.

What is the difference between TISAX assessment levels?

Level 1 requires only a self-assessment questionnaire. Level 2 adds a plausibility check, typically by phone, from an approved provider. Level 3 requires a full on-site audit, reserved for the most sensitive data and prototype protection cases.

What does a TISAX assessment cost for a mid-sized supplier?

External auditor fees for German SMEs typically run 4,000 to 8,000 euros depending on level. Including internal preparation and consulting support, total first-year project costs commonly reach 15,000 to 51,000 euros.

How is TISAX different from ISO 27001?

ISO 27001 certifies a general information security management system recognized across industries. TISAX is an automotive-specific assessment based on the VDA ISA catalog, itself aligned with ISO 27001 controls, and results are exchanged only through the ENX portal.

How long does TISAX preparation take and how long is the label valid?

A first-time Level 2 assessment typically takes two to four months of preparation, depending on how mature existing security practices are. A label is valid for three years, after which the supplier must complete a reassessment.

Is there funding available for TISAX preparation in the German Mittelstand?

Some German states offer digitalization and cybersecurity funding programs that cover part of the consulting cost for information security projects, though TISAX-specific funding lines are rare. Suppliers should check current regional programs, since availability changes frequently.

Building better software Contact us together