HomeFrameworksInformation Security & PrivacyTISAX

Framework  Information Security & Privacy

TISAX

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's shared assessment and exchange mechanism for supplier information security, run by the ENX Association on behalf of the German Association of the Automotive Industry (VDA).

Suppliers are assessed against the VDA Information Security Assessment (ISA) catalog; ISA version 6 has applied to assessments commissioned since April 1, 2024. Results are not published as certificates but as labels on the ENX portal that the supplier shares with the OEMs and partners that require them.

Labels currently cover confidentiality (Confidential, Strictly Confidential), availability (High Availability, Very High Availability), prototype protection and data protection objectives.

The assessment level depends on the protection need: AL1 is a self-assessment, AL2 is a remote plausibility check of the self-assessment by an audit provider, and AL3 is an on-site assessment with interviews and inspection.

To pass, the supplier must reach maturity level 3 across the requirements, meaning the ISMS is documented and demonstrably operated: an information security policy set, risk management, asset classification, access control, supplier security, incident management, business continuity, and for prototype and data protection objectives, the corresponding specialized policies.

Labels are valid for three years.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedISA policy set v2by name, on record
Assessment Level Readywith AllyMatter
Label It the Modern WayEvery ISA policy, acknowledged before the assessment
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every name on record
Who read which version, and when
03
Hand the audit provider the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Contractual. Suppliers, service providers and development partners whose automotive customers (mainly German OEMs and tier-one suppliers, increasingly others worldwide) require TISAX labels before sharing information with a high protection need. The customer specifies the assessment objectives and level.

What the assessor asks to see

ENX participant and scope registration; completed ISA self-assessment with maturity ratings; information security policy and ISMS documentation; risk assessment and treatment; asset inventory and classification; access control and identity management records; supplier and partner security agreements; incident management records; business continuity and backup evidence; for prototype protection, physical security and handling procedures; for data protection, GDPR processing documentation; on-site inspection at AL3.

Where the requirement sits: VDA ISA controls (information security, prototype protection, data protection) at maturity levels 0-5

Assessment levels and labels

AL1: self-assessment only, no label of practical value to most customers. AL2: audit provider reviews the self-assessment and evidence remotely. AL3: full on-site assessment.

With ISA 6 the former Info High and Info Very High labels were split into confidentiality labels (Confidential, Strictly Confidential) and availability labels (High Availability, Very High Availability); holders of the old labels were assigned the new confidentiality labels automatically. Prototype protection and data protection objectives carry their own labels.

What AllyMatter does here

Policy layer of the ISA catalogue.

AllyMatter publishes this site.

Assessors

Who assesses TISAX

An ENX-approved TISAX audit provider (approval decided by the TISAX Committee) using auditors qualified for the ISA. Only approved providers can perform AL2 and AL3 assessments that produce labels.

Accredited by ENX Association approves audit providers and monitors their quality; there is no national accreditation body in the chain, although many providers are also accredited certification bodies for ISO 27001.

Public register of assessors: https://portal.enx.com/en-us/tisax/xap/

BSI Group Deutschland GmbHOn the public register
What they do
Assessor
Which standards
On the public register for TISAX.
Standards
TISAX
Pricing
Not published
Bureau Veritas ServicesOn the public register
What they do
Assessor
Which standards
On the public register for TISAX.
Standards
TISAX
Pricing
Not published
DEKRA Certification GmbHOn the public register
What they do
Assessor
Which standards
On the public register for TISAX.
Standards
TISAX
Pricing
Not published
DNV Business Assurance Zertifizierung GmbHOn the public register
What they do
Assessor
Which standards
On the public register for TISAX.
Standards
TISAX
Pricing
Not published
DQS GmbHOn the public register
What they do
Assessor
Which standards
On the public register for TISAX.
Standards
TISAX
Pricing
Not published

Consultants

Who helps with TISAX

Yes. Information security consultancies, especially in Germany and Central Europe, offer ISA gap assessments, ISMS documentation, self-assessment preparation and audit accompaniment. Engagements typically run three to nine months before the audit.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a TISAX consultant listing yet. Claim yours →

Related reading

  1. Transition to TISAX VDA ISA version 6An assessment body explains the ISA 6 label rename, the new availability label and how existing labels carry over.DNV
  2. What is TISAX? The complete guide to automotive information security assessmentsWalks through assessment levels, the ENX exchange model and what an auditor tests at each level.NRI Secure

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for TISAX

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of TISAX in AllyMatter

Approve the policies TISAX asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.