TISAX

TISAX (Trusted Information Security Assessment Exchange) is an assessment and exchange mechanism for information security in the automotive industry. Its yardstick is the VDA ISA questionnaire. The ENX Association runs the mechanism, approves audit providers and monitors quality. The outcome is not a certificate but an assessment result with labels that the participant shares deliberately.

ISMSLast reviewed:

A TISAX requirement usually arrives the same way: a line in a customer contract, a field in a supplier portal, or an email from a purchasing department, with a date attached and very little explanation. If you are not already inside the German automotive supply chain, three things are worth knowing before you price the work: nobody is legally obliged to hold TISAX, the obligation is contractual, and what you obtain at the end is not a certificate.

Why the mechanism exists

The automotive industry continuously exchanges information with suppliers and service providers that has to be protected before publication: design data, prototypes, commercial terms, personal data. Before TISAX, each manufacturer assessed its partners itself. A supplier with a dozen customers went through a dozen largely identical audits. TISAX addresses exactly that: you are assessed once, and the result can then be shared many times.

That is also the reason a customer will rarely accept a substitute. The point of the mechanism is not only the assessment but the shared, comparable format in which results circulate.

Who runs it

The ENX Association is the custodian. It describes its own role as that of a governance organisation within TISAX: it approves audit providers and monitors both the quality of execution and the assessment results. ENX does not carry out the assessments; that is done by the approved audit providers.

The basis: the VDA ISA catalogue

Assessments are conducted against the VDA Information Security Assessment, VDA ISA for short. This questionnaire is the substantive yardstick of the mechanism and covers, alongside classical information security, prototype protection and data protection. It is maintained by the ENX working group ISA, which took over authorship from the VDA in 2019; the catalogue is still published through the VDA.

Which catalogue edition applies to your assessment

The questionnaire is revised over time, and which edition governs is decided by the date the assessment is commissioned, not the date of the audit itself. That is the detail project plans most often get wrong.

Assessment commissionedCatalogue edition permitted
before 1 January 2027may still be carried out under ISA 6
from 1 January 2027ISA2027

ISA2027 was published on 1 July 2026; ENX provides it in its download area together with a document comparing it to ISA 6. For the continued use of the older edition, ENX also names a closing date: an initial assessment under ISA 6 can still be opened up to March 2027.

Two questions follow from this, and they belong before the engagement is placed, not after. Which edition does the audit provider intend to use? And does the commissioning date still fall inside the window you want? A few days either side of the year-end decide which catalogue governs the assessment, and with it the scope of preparation.

Assessment objectives and TISAX labels

A process begins with the selection of assessment objectives. These describe what kind of information, with what protection needs, lies within the assessment scope, for instance information with high or very high protection needs, confidential information, availability requirements, prototype protection or data protection. At least one objective has to be selected, and several are possible. Passing the assessment yields the corresponding TISAX labels. Objective and label therefore denote the same thing at two points in the process: at the start as a goal, at the end as a result.

Which labels are demanded is decided by the customer. Settle that before you place the engagement rather than after: extending the scope afterwards generally means a fresh assessment. Where several customers demand different labels, it is worth collecting all of their requirements before scoping, because a second scope is considerably more expensive than a wider first one.

Assessment levels: how deep the review goes

Independently of the objective, the assessment level determines the depth of the review.

LevelWhat the audit provider does
AL 1Essentially a self-assessment. What is checked is only that a completed self-assessment exists, not its content. This result is not used in the TISAX exchange.
AL 2Plausibility check of the self-assessment, predominantly by web conference or otherwise remotely, supported by evidence and interviews.
AL 3Comprehensive verification: review of documents, interviews on site, inspection of local conditions and processes.

Higher levels include the lower ones. A result at assessment level 3 therefore automatically satisfies requests aimed at assessment level 2. What each level actually assesses, and what drives the scope and the cost, is covered in TISAX requirements, levels and costs.

Validity and the exchange of results

A TISAX assessment result is valid for three years. After that, a fresh full assessment of the requirements defined in the scope is required. Where nonconformities are found in an initial assessment, temporary labels can be issued; these expire nine months after the closing meeting of the initial assessment, or apply until all nonconformities have been resolved, whichever comes first.

The exchange is the real substance of the mechanism. The participant keeps control of its result and decides whether to publish it within the TISAX community or to release it to individual partners through their participant ID.

How it relates to ISO/IEC 27001

TISAX and ISO/IEC 27001 pursue similar goals by different routes. ISO/IEC 27001 is sector-neutral, sets requirements for a management system and is certifiable. TISAX is sector-specific, assesses against its own questionnaire, and ends not with a certificate but with a shared assessment result.

An existing ISMS makes the preparation considerably easier, because the policy, the risk process, the roles and the records are already in place, but it does not replace the assessment. Conversely, a TISAX label is no substitute for an ISO 27001 certificate when a customer outside the automotive sector asks for one. Suppliers serving both markets generally end up maintaining one set of controls and two forms of external evidence.

What to settle before you start

Four questions decide effort and timing. Which assessment objectives do your customers actually require? Which sites and which processes belong in the scope? Which assessment level is demanded? And how much lead time does your organisation need before the evidence will hold up? The binding rules of the mechanism are set out in the TISAX Participant Handbook published by the ENX Association.

What can be prepared

What can be prepared is the part that costs suppliers the most time, and it is rarely the catalogue. It is the question of which sites, systems and people-functions are affected at all. For the higher protection levels and for prototype protection the physical layer is decisive.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework