Information security in the automotive industry
TISAX® is the standard for information security assessments in the automotive industry – operated by the ENX Association on behalf of the VDA. We guide you from gap analysis and internal audits to your TISAX label, and always obtain at least three quotes from ENX-approved audit providers for your assessment.
TISAX®
Information security in the automotive industry

With TISAX® (Trusted Information Security Assessment Exchange) the automotive industry has created a binding standard to ensure the secure handling of sensitive information between manufacturers, suppliers and service providers. The foundation is ISO/IEC 27001, complemented by industry-specific requirements.
For many companies a TISAX label is today a prerequisite for collaboration with OEMs and large suppliers — making it a decisive competitive factor. Since its launch in 2016, more than 21,000 locations worldwide have been assessed under TISAX.
OUR SERVICES ON THE WAY TO YOUR TISAX LABEL
TISAX® is a registered trademark of the ENX Association. TISAX assessments are conducted exclusively by ENX-approved audit providers – VamiSec is not an audit provider, but provides vendor-neutral support for preparation, internal audits, quote procurement and the assessment.
What you should know about TISAX
An assessment, not a certificate
TISAX is an assessment and exchange mechanism, not a classic certification: after the assessment you receive TISAX labels, which you share with selected partners via the ENX portal. Labels are valid for up to three years.
Operated by ENX on behalf of the VDA
TISAX started in 2016 and is now the industry’s common standard: more than 21,000 locations have been assessed worldwide, and over ten vehicle manufacturers plus thousands of suppliers rely on it.
Assessed against the VDA ISA
Assessments are based on the VDA’s ISA catalogue with the modules information security, prototype protection and data protection. ISA 6 applies to current orders – assessments ordered from 1 January 2027 will run under ISA2027.
Assessment levels AL 1–3
The protection need determines the assessment depth: AL 1 serves internal purposes, AL 2 is a plausibility check based on evidence and remote interviews, AL 3 a comprehensive on-site assessment with interviews and process observation.
Assessment objectives & labels
The objectives cover confidentiality (Confidential, Strictly Confidential), availability (High/Very High Availability), prototype protection (e.g. Proto Parts, Proto Vehicles) and data protection (Data, Special Data) – your scope determines the labels.
Three phases to the label
Registration in the ENX portal, assessment by an ENX-approved audit provider, exchange of results with your partners. If findings remain open, a corrective action plan and a follow-up assessment secure temporary labels.
New: VDA ISA2027 – published in July 2026
For TISAX’s tenth anniversary the VDA released the successor catalogue ISA2027 and switched to year-based versioning with a fixed annual cycle. ISA2027 applies to all assessments ordered from 1 January 2027 – the order date in the ENX portal is decisive, and existing labels remain valid. In terms of content, the information security controls have been extensively revised, prototype protection has been restructured and supply chain requirements tightened; many former recommendations become mandatory. Our gap analyses and action plans are already ISA2027-ready.
The path to your TISAX label
Scoping & registration
Definition of the assessment scope, selection of assessment objectives and level (AL 2/3), and registration as a TISAX participant in the ENX portal.
Gap analysis & action plan
Detailed analysis of the gaps against the current VDA ISA (ISA 6 or ISA2027) and a prioritised action plan with effort estimates.
ISMS & industry-specific controls
Building or extending the ISMS including policies, processes and roles, plus implementation of prototype protection and data protection requirements.
Internal audits & mock audit
Internal audits per ISO 27001 clause 9.2 and a trial audit against the VDA ISA ensure audit readiness – remaining gaps are closed in a targeted way.
Audit provider selection – at least 3 quotes
We obtain at least three comparative quotes from ENX-approved audit providers, evaluate scope, timelines and terms, and support the commissioning.
Assessment support through to the label
Expert support during the initial assessment, help with corrective actions and follow-up, and release of the results to your customers via the ENX portal.
Protect Your Organization Now!
Contact us for an individual consultation and security solution tailored to your requirements.
Valeri Milke, CEO of VamiSec
"Only when all instruments are well-tuned does your organization become secure and compliant."
