Skip to content
DEEN
Book a call

Industry standard Market-driven · Switzerland, EU, Germany

TISAX (Trusted Information Security Assessment Exchange).

Short answer

TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue. It is not a law and not a public certificate, but a result label shared via the ENX portal and contractually required by vehicle manufacturers and large suppliers. The ENX Association was founded by several European vehicle manufacturers, national automotive associations and suppliers; TISAX is therefore not limited to German manufacturers but is carried by the European industry and performed by audit providers worldwide.

01 Triggers

When does TISAX apply to you?

TISAX may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.

  • Activity: Supplier to the automotive industry (Applies): Anyone supplying the automotive industry is contractually required by manufacturers and large tier-1 suppliers to hold a valid TISAX result before sensitive design or production data is exchanged.
  • Industry: Manufacturing (applies if additionally: Activity: Supplier to the automotive industry) (Likely applies): In manufacturing, vehicle manufacturers regularly check their supply chain via the ENX portal for a valid TISAX result before awarding contracts - this concerns you if you specifically operate as an automotive supplier.
  • Role towards customers: Supplier (applies if additionally: Activity: Supplier to the automotive industry) (Likely applies): As a supplier in the automotive value chain, a TISAX result frequently becomes a condition for new contracts and for exchanging development data. This does not apply to suppliers outside the automotive industry.
  • Markets: EU, Germany, Worldwide (applies if additionally: Activity: Supplier to the automotive industry) (Recommend individual review): TISAX is not a purely German matter: the assessment procedure is carried by several European vehicle manufacturers and associations and is performed by audit providers worldwide, which is why, as an automotive supplier, it can become a condition outside Germany as well.

Exceptions

  • Not a law and not a state obligation; the requirement arises exclusively contractually via customers in the automotive supply chain.
  • Assessment Level 1 (pure self-assessment without external review) does not lead to a TISAX label and is not accepted by most vehicle manufacturers as full evidence.

02 Obligations

What does TISAX require?

  • Registration in the ENX portal and definition of the assessment scope (assessment objective: information security, prototype protection and/or data protection when connecting third parties)
  • Choice of the appropriate assessment level depending on the customer's protection needs: AL1 self-assessment without a label, AL2 remote audit by an accredited assessment provider (the standard case for most participants), AL3 on-site audit for particularly sensitive information or vehicle prototypes
  • Implementation of the requirements from the VDA ISA assessment catalogue
  • Carrying out the assessment via an assessment provider approved by ENX

03 Evidence

What evidence is needed?

  • TISAX result/label in the ENX portal, shared specifically with individual customers (not a public certificate as with ISO 27001)
  • For AL2, the result is stored in the ENX portal, visible to TISAX participants
  • Sharing of the result with individual customers is done by the assessed company itself in the portal

04 Penalties

What are the consequences of violations?

No fine, since it is not a law; in practice: without a valid TISAX result, exclusion from vehicle manufacturers' supplier lists and tenders is a risk, as is termination or non-renewal of existing supply contracts.

05 Related

What is connected with it?

06 Open

What is still uncertain?

  • The complete list of ENX members (exactly which vehicle manufacturers/associations, from which countries) was not conclusively checked in this session; enx.com/en-US/ only generally confirms 'automotive manufacturers, national automotive associations, and automotive suppliers' without a name list.
  • vda.de was unreachable in this session (HTTP 404 on two attempted paths); statements on the VDA ISA catalogue come exclusively from secondary sources (search results, the ENX page), not read from the VDA itself.
  • The exact validity period of a TISAX result and details on VDA ISA version 6.0/2027 are evidenced only from secondary sources (search result summaries), not checked against the ENX or VDA original text in this session.
  • The AL1/AL2/AL3 detailed description comes from secondary sources (cis-cert, kopexa, further search results), not from the ENX or VDA original text in this session.

07 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about TISAX.

Is TISAX only relevant for German vehicle manufacturers?

No. TISAX is carried by the ENX Association, a non-profit organisation founded by several vehicle manufacturers, national automotive associations and suppliers in Europe. The assessment procedure is applied across Europe, and assessments are performed by assessment providers worldwide, not only in Germany.

What is the difference between ISO 27001 and TISAX?

ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an automotive industry assessment procedure based on the VDA ISA catalogue, with a label instead of a certificate, and is contractually required by vehicle manufacturers.

What do assessment levels AL1 to AL3 mean?

AL1 is a pure self-assessment without external review and does not lead to a TISAX label. AL2 is the level typical for most participants: a remote audit by an accredited assessment provider, whose result is shared in the ENX portal. AL3 is the most comprehensive level, with an on-site audit, for particularly sensitive information or vehicle prototypes.

Do you get a public certificate with TISAX?

No. The result is stored in the ENX portal, and the assessed company shares it specifically with individual customers. There is no publicly viewable certificate as with ISO 27001.

Does TISAX apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light