Compliance

TISAX Compliance: Automotive Data Security Explained

Learn what TISAX compliance is, how VDA ISA assessments work, and what automotive suppliers must do to earn a TISAX label. Covers AL2, AL3, and key controls.

Editorial Team ·
9 min read intermediate

Introduction

A single data breach inside a Tier-2 automotive supplier cost Volkswagen an estimated $800 million in intellectual property when 19,000 design files leaked between 2010 and 2015. TISAX compliance — the Trusted Information Security Assessment Exchange — exists precisely because the automotive industry cannot rely on generic security certifications. A supplier holding an ISO 27001 certificate but lacking automotive-specific controls for prototype handling can still expose blueprints for next-generation vehicles to competitors or nation-state actors. TISAX was built to close that gap. If you supply parts, software, engineering services, or IT systems to any major OEM, understanding TISAX is no longer optional; it is a market entry requirement.

What Is TISAX Compliance?

TISAX (Trusted Information Security Assessment Exchange) is a standardized information security assessment mechanism created for the global automotive supply chain. The ENX Association, a non-profit representing European automotive manufacturers and their ecosystems, governs it. TISAX was introduced in 2017 to replace the patchwork of individual OEM audit requests that forced suppliers to undergo dozens of separate security reviews for each customer relationship.

The mechanism works in two steps. First, an independent accredited auditor evaluates your organization against the VDA ISA (Information Security Assessment) control catalog. Second, you share those results through the ENX portal — a controlled exchange where you decide exactly which business partners can see your assessment. The result is a “once tested, recognized by all” model. You pass one assessment; BMW, Audi, Bosch, and Continental can all access your label without commissioning their own audit.

TISAX is not a certification in the traditional sense. You do not receive a certificate. You receive a TISAX label — a digital record in the ENX portal that authorized partners can verify directly. Labels are valid for three years, after which reassessment is required.

How TISAX Compliance Works

The TISAX process follows five structured phases that take most organizations between four and twelve months to complete, depending on their existing security maturity.

Phase 1 — Registration. You register your organization in the ENX portal, define which sites and business processes are in scope, and select your required assessment labels — typically “Information Security,” “Prototype Protection,” or “Data Protection.” The label you need is determined by the type of data you handle for your automotive customer.

Phase 2 — Self-Assessment. You complete the VDA ISA 6.0 questionnaire internally, scoring each control on a maturity scale of 0 to 5. To earn a TISAX label, you must reach at least Maturity Level 3 — meaning processes are documented, implemented, and consistently followed — across all required controls.

Phase 3 — Gap Remediation. Most organizations identify gaps during self-assessment. Common weak areas include incomplete asset inventories, undocumented supplier security requirements, and inadequate physical access controls for prototype handling areas. You resolve these before engaging an auditor.

Phase 4 — Formal Audit. An ENX-accredited audit provider reviews your self-assessment. The depth of this review depends on your Assessment Level (AL):

  • AL2 — A remote plausibility check (usually a structured video interview), suitable for sensitive information that is not at the highest protection tier.
  • AL3 — A full on-site audit with evidence verification and, in some cases, penetration testing, required for very high protection requirements such as development prototypes or strictly confidential vehicle platform data.

Phase 5 — Label Issuance and Exchange. A successful audit triggers label issuance in the ENX portal. You grant access to specific partner organizations. Those partners see your label status — not the detailed findings — preserving confidentiality while proving compliance.

TISAX vs ISO 27001: Key Differences

Both frameworks address information security management, but they serve different purposes and different audiences.

DimensionTISAXISO 27001
ScopeAutomotive supply chainAny industry, any organization
Control catalogVDA ISA 6.0 (automotive-specific)Annex A (114 generic controls)
Prototype protectionMandatory module for relevant scopesNot addressed
Result sharingENX portal (controlled, partner-visible)Certificate issued by accreditation body
Validity3 years3 years (with annual surveillance audits)
Assessment modelAL2 (remote) or AL3 (on-site)Always includes on-site stage 1 + stage 2
Automotive OEM acceptanceRequired by most OEMsNot sufficient on its own
RelationshipIncorporates ~75% of ISO 27001 controlsFoundational standard; TISAX builds on it

If you already hold an ISO 27001 certificate, you have a significant head start — your ISMS documentation, risk assessment methodology, and many technical controls will overlap directly with the VDA ISA requirements. However, you will still need to address automotive-specific gaps, particularly around prototype security and supply chain controls, before undergoing a TISAX assessment. Linking your existing ISO 27001 ISMS to the VDA ISA gap analysis is the most efficient path to your first label.

Real-World Use Cases

Tier-1 and Tier-2 parts suppliers. The majority of TISAX labels are held by direct OEM suppliers (Tier-1) and their component manufacturers (Tier-2). When BMW or Mercedes-Benz shares vehicle architecture documents with a seating supplier, that supplier must demonstrate AL2 compliance to receive the files. Without a valid label, the OEM cannot legally transfer the data under its own contractual security obligations.

Software and IT service vendors. Embedded software developers, infotainment platform vendors, and cloud service providers handling vehicle telemetry increasingly receive TISAX requirements in RFQ (request for quotation) documents. A cybersecurity firm helping an OEM with penetration testing or NIST CSF alignment will often need TISAX alongside SOC 2 to satisfy the automotive customer’s vendor risk requirements.

Logistics and engineering service providers. Companies that physically handle prototype vehicles or design documents — logistics firms transporting pre-production models, engineering agencies receiving CAD files — need Prototype Protection labels at AL3. The physical security controls in that label module, covering access zones, camera restrictions, and visitor management, go significantly beyond what ISO 27001 requires.

Common Mistakes to Avoid

Scope creep on the first assessment. Many organizations define their initial scope too broadly, including every site and system in the company. Start with the minimum scope that satisfies your OEM customer’s requirement. A smaller, well-controlled scope produces a faster, lower-cost audit and a cleaner result than a sprawling scope with many findings.

Treating TISAX as a one-time project. A TISAX label is only valid while your controls remain at Maturity Level 3. OEMs can request evidence of continued compliance between reassessments. Organizations that view TISAX as a project rather than an ongoing program are typically the ones that fail their three-year renewal audit because they allowed controls to degrade.

Ignoring supplier management requirements. The VDA ISA 6.0 requires you to extend security requirements to your own sub-suppliers who touch automotive data. Failing to document and enforce supplier security obligations is one of the most frequently cited audit findings in AL2 assessments.

Selecting the wrong assessment level. Requesting AL2 when your OEM customer requires AL3 wastes your assessment investment and delays label issuance. Confirm the required level explicitly in writing with each customer before registering in the ENX portal.

Neglecting the encryption and access control requirements. VDA ISA 6.0 is specific about cryptographic standards for data at rest and in transit. Controls that reference “strong encryption” should be mapped to concrete standards — AES-256 for storage, TLS 1.2 minimum for transit — with documented evidence based on encryption at rest vs in transit practices, and enforced rather than merely recommended.

Getting Started with TISAX Compliance

Identify your OEM customer’s requirement. Ask your customer contact for the specific TISAX label type and assessment level they require. Get it in writing in the contract or supplier security annex. This single step prevents the most common mis-scoping errors.

Register on the ENX portal. Go to portal.enx.com and create your organization’s TISAX participant account. Download the current version of the VDA ISA questionnaire directly from the portal — do not use third-party copies, which may be outdated.

Complete the VDA ISA self-assessment. Score every applicable control honestly. Inflated self-scores that the auditor subsequently downgrades are treated as a finding in their own right and signal poor security culture to your OEM customer.

Run a formal gap analysis. Map your VDA ISA gaps against your existing ISO 27001 ISMS controls, NIST Cybersecurity Framework alignment, and any applicable compliance work you have already done (such as SOC 2 encryption controls). Prioritize closure of AL3 physical security and prototype handling gaps first — these take the most time to implement.

Select an accredited audit provider. The ENX portal lists all approved audit providers. Select one with demonstrable automotive sector experience. Request references from previous TISAX clients in your industry segment.

Schedule the audit after remediation. Give yourself at least four to six weeks between completing remediation and audit scheduling to allow evidence to accumulate. Auditors look for operating history — a firewall rule added one week before the audit carries less weight than one documented six months ago.

Your TISAX label will appear in the ENX portal within days of a successful audit. Once live, grant access to the specific OEM and Tier-1 partners who require it. Internally, schedule your next self-assessment for year two to catch any control degradation well before the three-year renewal deadline. For broader data governance alignment, explore how TISAX intersects with GDPR Article 32 encryption requirements — many automotive suppliers operating in Europe must satisfy both simultaneously.

Watch to understand the full TISAX process: how the VDA ISA questionnaire maps to assessment levels, what auditors look for at AL2 vs AL3, and how results flow through the ENX exchange portal.

TISAX Compliance Checklist

Use this checklist to track your readiness. Each item cites the VDA ISA 6.0 control domain it corresponds to.

Governance and ISMS

  1. Define information security policy signed by top management (VDA ISA 6.0 — Policy and Organisation).
  2. Assign a formally designated Information Security Officer with documented authority (VDA ISA 6.0 — Organisation).
  3. Complete a formal risk assessment covering all in-scope assets and processes (VDA ISA 6.0 — Risk Management).
  4. Document and test an incident response plan including automotive-specific breach notification obligations (VDA ISA 6.0 — Event Management).
  5. Conduct an internal ISMS review at least annually and document management review outcomes (VDA ISA 6.0 — ISMS Improvement).

Access and Identity Controls

  1. Implement role-based access controls with least-privilege enforcement for all in-scope systems (VDA ISA 6.0 — Access Control).
  2. Enforce multi-factor authentication for remote access to systems holding automotive confidential data (VDA ISA 6.0 — Access Control).
  3. Maintain and review user access rights at minimum quarterly; revoke promptly upon role change or departure (VDA ISA 6.0 — Access Control).

Data and Encryption

  1. Encrypt all confidential automotive data at rest using AES-256 or equivalent approved cipher (VDA ISA 6.0 — Cryptography).
  2. Enforce TLS 1.2 or higher for all data in transit; disable deprecated protocols (TLS 1.0/1.1, SSL) (VDA ISA 6.0 — Cryptography).
  3. Document encryption key management procedures including rotation schedules and key storage (VDA ISA 6.0 — Cryptography).

Physical Security (required for Prototype Protection label)

  1. Implement controlled physical access zones for areas handling prototype data or prototype vehicles (VDA ISA 6.0 — Physical Security).
  2. Enforce and document a photography and recording prohibition in prototype areas (VDA ISA 6.0 — Physical Security).
  3. Maintain visitor registers with escort procedures for all non-authorized personnel (VDA ISA 6.0 — Physical Security).

Supplier Management

  1. Document security requirements in all contracts with sub-suppliers who process automotive confidential data (VDA ISA 6.0 — Supplier Relationships).
  2. Conduct periodic supplier security reviews or request evidence of equivalent compliance (VDA ISA 6.0 — Supplier Relationships).

Audit Readiness

  1. Register your organization and defined scope on the ENX portal at portal.enx.com (ENX TISAX Participant Requirements).
  2. Complete an honest VDA ISA 6.0 self-assessment and address all gaps with documented Maturity Level 3 evidence (VDA ISA 6.0 — all domains).
  3. Engage an ENX-accredited audit provider appropriate for your required assessment level (AL2 or AL3) (ENX TISAX Audit Provider Requirements).

FAQ

Common questions — answered in plain English.

What is TISAX compliance?
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and result-sharing mechanism for the automotive industry, governed by the ENX Association. It allows suppliers to demonstrate their security posture to OEM partners without repeating audits for every customer. Results are valid across the entire automotive supply chain.
Is TISAX the same as ISO 27001?
No. TISAX is based on the VDA ISA questionnaire, which incorporates roughly 75% of ISO 27001 controls but adds automotive-specific requirements — such as prototype protection and third-party connection controls — that ISO 27001 does not cover. ISO 27001 certification gives you a strong head start but does not replace a TISAX assessment.
What are the TISAX assessment levels?
TISAX has three assessment levels. AL1 is a self-assessment not used for official sharing. AL2 is a remote plausibility check by an accredited auditor, suitable for sensitive but moderate-risk information. AL3 requires an on-site audit with full system verification, used when very high protection requirements apply — for example, prototype data or top-secret development information.
How long is a TISAX label valid?
TISAX labels are valid for three years from the date of the assessment. After three years, you must undergo a reassessment to renew your label and continue sharing results with automotive partners via the ENX portal.
What is the VDA ISA questionnaire?
The VDA ISA (Information Security Assessment) is the official control catalog used in every TISAX assessment. It is developed by the VDA (Verband der Automobilindustrie) and organized into domains covering information security management, access control, physical security, prototype protection, and supplier management. VDA ISA 6.0 became mandatory for all new assessments from April 2024.
Who needs TISAX certification?
Any supplier, service provider, or technology partner that handles confidential automotive data — including engineering documents, prototype designs, customer vehicle data, or source code — may be required by an OEM (original equipment manufacturer) to hold a valid TISAX label as a condition of the business relationship.

References

  1. [1]
  2. [2]
    VDA ISA 6.0 — Information Security Assessment CatalogVDA (Verband der Automobilindustrie), 2024
  3. [3]
  4. [4]
  5. [5]