01Governance: ENX Association and VDA
TISAX is operated by the ENX Association: it defines the requirements for audit providers (TISAX ACAR), accredits them and monitors audit quality; the VDA ISA catalogue is published by the German Association of the Automotive Industry (VDA). TISAX is not a classic certification scheme but an exchange mechanism: active participants have themselves assessed and release their results, while passive participants request the results of their business partners — both roles can be held in parallel. Results and labels are accessible exclusively via the ENX platform, not publicly.
02The VDA ISA Catalogue: Three Criteria Blocks, Maturity Model
The VDA ISA comprises three criteria catalogues: information security as the core module, plus prototype protection and data protection as additional modules depending on the assessment objective. Evaluation is not binary but based on a maturity model from 0 to 5; the target is generally maturity level 3 ("established"), and higher actual values are capped at the target maturity level when calculating the result. The current basis is ISA 6 (version 6.0.3), mandatory for all assessments commissioned since April 1, 2024. On July 1, 2026, the VDA published the successor version ISA2027: it applies to assessments commissioned from January 1, 2027 onwards, updates the mappings to ISO/IEC 27001:2022 and NIST CSF 2.0 and restructures prototype protection from five control groups into two domains; future ISA versions will be released annually and carry the year they become mandatory in their name.
03Assessment Levels AL1 to AL3
The assessment level determines the depth of the assessment and is derived from the protection needs of the assessment objectives — it is not a free choice for the company. At AL1, the audit provider merely confirms the existence of a fully completed self-assessment without verifying its content; AL1 results are not used within TISAX and do not lead to a label. AL2 is a plausibility check of the self-assessment based on evidence and interviews, usually conducted via web conference, and applies to assessment objectives with high protection needs. AL3 requires a comprehensive on-site assessment with document inspection and interviews and applies to very high protection needs, for example the "Strictly confidential" assessment objective.
04Labels and Three Years of Validity
Successful assessments result in TISAX labels per assessment objective: for information security "Confidential" and "Strictly confidential" (since April 1, 2024; previously "Info high"/"Info very high") as well as "High availability" and "Very high availability", for prototype protection "Proto parts", "Proto vehicles", "Test vehicles" and "Proto events", and for data protection "Data" and "Special data". Labels are valid for three years from the closing meeting of the assessment; there are no surveillance audits during this period, and afterwards a full re-assessment is required. If minor non-conformities are identified in the initial assessment, temporary labels can be issued based on a reviewed corrective action plan — they expire nine months after the closing meeting of the initial assessment.
05Scoping and Typical Process
The assessment scope is site-based and is defined at registration. In most cases, the predefined standard scope is used, the description of which cannot be modified; custom scopes remain reserved for special cases, and for corporate groups with many locations the Simplified Group Assessment is available. The process follows a fixed pattern: registration as a participant with ENX including scope and assessment objectives, self-assessment based on VDA ISA and closing of identified gaps, assessment by an ENX-accredited audit provider, in case of non-conformities corrective actions with a follow-up assessment within the nine-month window, and finally releasing the results to business partners via the ENX platform. In practice, preparation usually takes considerably more time than the assessment itself.
06TISAX and ISO 27001: Related, but Not Interchangeable
The VDA ISA is based on core aspects of ISO/IEC 27001, but the procedure differs considerably. TISAX evaluates via maturity levels rather than a pure conformity statement, works with standardized, site-based scopes instead of a freely defined ISMS scope, and adds industry-specific modules for prototype protection and data protection that ISO 27001 does not cover. The outcome is not a public certificate but labels that are shared with other participants exclusively via the ENX platform. In addition, a TISAX label is valid for three years without surveillance audits, whereas ISO 27001 certificates provide for annual surveillance audits within a three-year cycle. An existing ISO 27001 certificate therefore generally does not replace a TISAX label — but a well-established ISMS shortens the preparation considerably, as documentation and processes can largely be reused.