TISAX is operated by the ENX Association: it defines the requirements for audit providers (TISAX ACAR), accredits them and monitors audit quality; the VDA ISA catalogue is published by the German Association of the Automotive Industry (VDA). TISAX is not a classic certification scheme but an exchange mechanism: active participants have themselves assessed and release their results, while passive participants request the results of their business partners — both roles can be held in parallel. Results and labels are accessible exclusively via the ENX platform, not publicly.
TISAX: Information Security in the Automotive Supply Chain
How the automotive industry's assessment and exchange mechanism works: from governance by the ENX Association and the VDA ISA catalogue to assessment levels, labels and three years of validity.
21,000+locations assessed since the 2016 launch (according to ENX figures)
3criteria catalogues in the VDA ISA: information security, prototype protection, data protection
3years of label validity from the closing meeting — no surveillance audits
9months until temporary labels expire after the closing meeting of the initial assessment
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's established mechanism for assessing the information security of suppliers and service providers against a uniform benchmark and sharing the results among business partners. Instead of undergoing repeated individual customer audits, a company completes an assessment based on the VDA ISA catalogue and shares the result via the ENX Association's platform; numerous manufacturers and suppliers require valid TISAX labels as a prerequisite for doing business. According to ENX figures, more than 21,000 locations have been assessed since the launch in 2016. With the publication of VDA ISA2027 on July 1, 2026, the transition to an annual release cycle also begins — the new catalogue version is mandatory for assessments commissioned from January 1, 2027 onwards.
From ISA 6 to the annual release cycle
Key dates from ISA 6 and ISA2027 — tap a milestone for details.
Apr 1, 2024
ISA 6 mandatory
All assessments commissioned since this date run on ISA 6 (version 6.0.3). The new label names "Confidential" and "Strictly confidential" (previously "Info high"/"Info very high") also apply.
Jul 1, 2026
VDA ISA2027 published
The VDA publishes the successor version ISA2027, beginning the transition to an annual release cycle. It updates the mappings to ISO/IEC 27001:2022 and NIST CSF 2.0 and restructures prototype protection from five control groups into two domains.
Jan 1, 2027
ISA2027 mandatory
The new catalogue version is mandatory for assessments commissioned from this date onwards. Future ISA versions will be released annually and carry the year they become mandatory in their name.
The Essentials at a Glance
Six topic blocks — tap to expand.
Assessment Levels AL1 to AL3
The depth of the assessment is derived from the protection needs of the assessment objectives — it is not a free choice for the company.
- The audit provider merely confirms the existence of a fully completed self-assessment without verifying its content.
- AL1 results are not used within TISAX and do not lead to a label.
self-assessment
- A plausibility check of the self-assessment based on evidence and interviews, usually conducted via web conference.
- Applies to assessment objectives with high protection needs.
evidenceinterviewsweb conference
- A comprehensive on-site assessment with document inspection and interviews.
- Applies to very high protection needs, for example the "Strictly confidential" assessment objective.
on-sitedocument inspectioninterviewsStrictly confidential
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
TISAX Participant Handbook
Authoritative process document on registration, scoping, assessment levels, assessment objectives, labels and validity.
VDA ISA 6.0.3
Current assessment catalogue; the mandatory basis for all TISAX assessments commissioned since April 1, 2024.
VDA ISA2027
Successor version of the assessment catalogue, published on July 1, 2026; mandatory for assessments commissioned from January 1, 2027 onwards.
10 Years of TISAX – VDA ISA2027 Released
Official announcement with transition rules, the annual release cycle and key figures from ten years of TISAX.
Welcome to TISAX · ENX Portal
Official programme overview covering governance, audit provider accreditation (TISAX ACAR), participant roles and three-year validity.
Preparing for a TISAX Assessment?
We support you from the VDA ISA gap analysis all the way to assessment readiness — independent and audit-provider-neutral. Schedule a no-obligation initial consultation.