Book an Appointment

TISAX: Information Security in the Automotive Supply Chain

How the automotive industry's assessment and exchange mechanism works: from governance by the ENX Association and the VDA ISA catalogue to assessment levels, labels and three years of validity.

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's established mechanism for assessing the information security of suppliers and service providers against a uniform benchmark and sharing the results among business partners. Instead of undergoing repeated individual customer audits, a company completes an assessment based on the VDA ISA catalogue and shares the result via the ENX Association's platform; numerous manufacturers and suppliers require valid TISAX labels as a prerequisite for doing business. According to ENX figures, more than 21,000 locations have been assessed since the launch in 2016. With the publication of VDA ISA2027 on July 1, 2026, the transition to an annual release cycle also begins — the new catalogue version is mandatory for assessments commissioned from January 1, 2027 onwards.

The Essentials at a Glance

01

Governance: ENX Association and VDA

TISAX is operated by the ENX Association: it defines the requirements for audit providers (TISAX ACAR), accredits them and monitors audit quality; the VDA ISA catalogue is published by the German Association of the Automotive Industry (VDA). TISAX is not a classic certification scheme but an exchange mechanism: active participants have themselves assessed and release their results, while passive participants request the results of their business partners — both roles can be held in parallel. Results and labels are accessible exclusively via the ENX platform, not publicly.

02

The VDA ISA Catalogue: Three Criteria Blocks, Maturity Model

The VDA ISA comprises three criteria catalogues: information security as the core module, plus prototype protection and data protection as additional modules depending on the assessment objective. Evaluation is not binary but based on a maturity model from 0 to 5; the target is generally maturity level 3 ("established"), and higher actual values are capped at the target maturity level when calculating the result. The current basis is ISA 6 (version 6.0.3), mandatory for all assessments commissioned since April 1, 2024. On July 1, 2026, the VDA published the successor version ISA2027: it applies to assessments commissioned from January 1, 2027 onwards, updates the mappings to ISO/IEC 27001:2022 and NIST CSF 2.0 and restructures prototype protection from five control groups into two domains; future ISA versions will be released annually and carry the year they become mandatory in their name.

03

Assessment Levels AL1 to AL3

The assessment level determines the depth of the assessment and is derived from the protection needs of the assessment objectives — it is not a free choice for the company. At AL1, the audit provider merely confirms the existence of a fully completed self-assessment without verifying its content; AL1 results are not used within TISAX and do not lead to a label. AL2 is a plausibility check of the self-assessment based on evidence and interviews, usually conducted via web conference, and applies to assessment objectives with high protection needs. AL3 requires a comprehensive on-site assessment with document inspection and interviews and applies to very high protection needs, for example the "Strictly confidential" assessment objective.

04

Labels and Three Years of Validity

Successful assessments result in TISAX labels per assessment objective: for information security "Confidential" and "Strictly confidential" (since April 1, 2024; previously "Info high"/"Info very high") as well as "High availability" and "Very high availability", for prototype protection "Proto parts", "Proto vehicles", "Test vehicles" and "Proto events", and for data protection "Data" and "Special data". Labels are valid for three years from the closing meeting of the assessment; there are no surveillance audits during this period, and afterwards a full re-assessment is required. If minor non-conformities are identified in the initial assessment, temporary labels can be issued based on a reviewed corrective action plan — they expire nine months after the closing meeting of the initial assessment.

05

Scoping and Typical Process

The assessment scope is site-based and is defined at registration. In most cases, the predefined standard scope is used, the description of which cannot be modified; custom scopes remain reserved for special cases, and for corporate groups with many locations the Simplified Group Assessment is available. The process follows a fixed pattern: registration as a participant with ENX including scope and assessment objectives, self-assessment based on VDA ISA and closing of identified gaps, assessment by an ENX-accredited audit provider, in case of non-conformities corrective actions with a follow-up assessment within the nine-month window, and finally releasing the results to business partners via the ENX platform. In practice, preparation usually takes considerably more time than the assessment itself.

06

TISAX and ISO 27001: Related, but Not Interchangeable

The VDA ISA is based on core aspects of ISO/IEC 27001, but the procedure differs considerably. TISAX evaluates via maturity levels rather than a pure conformity statement, works with standardized, site-based scopes instead of a freely defined ISMS scope, and adds industry-specific modules for prototype protection and data protection that ISO 27001 does not cover. The outcome is not a public certificate but labels that are shared with other participants exclusively via the ENX platform. In addition, a TISAX label is valid for three years without surveillance audits, whereas ISO 27001 certificates provide for annual surveillance audits within a three-year cycle. An existing ISO 27001 certificate therefore generally does not replace a TISAX label — but a well-established ISMS shortens the preparation considerably, as documentation and processes can largely be reused.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ENX Association · 2025

TISAX Participant Handbook

Authoritative process document on registration, scoping, assessment levels, assessment objectives, labels and validity.

Verband der Automobilindustrie (VDA) · 2024

VDA ISA 6.0.3

Current assessment catalogue; the mandatory basis for all TISAX assessments commissioned since April 1, 2024.

Verband der Automobilindustrie (VDA) · 2026

VDA ISA2027

Successor version of the assessment catalogue, published on July 1, 2026; mandatory for assessments commissioned from January 1, 2027 onwards.

ENX Association · 2026

10 Years of TISAX – VDA ISA2027 Released

Official announcement with transition rules, the annual release cycle and key figures from ten years of TISAX.

ENX Association · 2026

Welcome to TISAX · ENX Portal

Official programme overview covering governance, audit provider accreditation (TISAX ACAR), participant roles and three-year validity.

Preparing for a TISAX Assessment?

We support you from the VDA ISA gap analysis all the way to assessment readiness — independent and audit-provider-neutral. Schedule a no-obligation initial consultation.