What is TISAX?

TISAX stands for Trusted Information Security Assessment Exchange. It is the automotive industry's shared way of assessing and proving information security. Rather than every carmaker running its own separate security audit on every supplier, the industry agreed on one common assessment and one platform to share the results. TISAX is governed by the ENX Association on behalf of the German automotive industry and its association, the VDA.

The assessment is built on the VDA ISA catalogue — the Information Security Assessment questionnaire maintained by the VDA. VDA ISA draws heavily on the ideas in ISO/IEC 27001, but it is tailored to what automotive OEMs and their supply chains actually worry about, including the protection of prototypes and the handling of personal data.

One thing to be clear about from the start: TISAX does not produce a classic certificate the way ISO 27001 does. It produces an assessment result and a label that you share, through the ENX exchange platform, with the customers who ask to see it. The label typically stays valid for three years. When people say they are 'TISAX certified', what they really mean is that they hold a valid TISAX label.

Who needs TISAX?

TISAX is for any organization that handles sensitive information belonging to an automotive customer. In practice, that is a wide net across the supply chain. It is a fit for:

  • Tier 1, Tier 2 and Tier 3 automotive suppliers of parts, systems, and materials
  • Engineering, design, and development firms that work on vehicle programs
  • Software, electronics, and connected-vehicle providers handling OEM data or code
  • Tooling, prototype, and testing businesses that receive pre-release designs and physical prototypes
  • IT, cloud, marketing, and back-office providers that process automotive customer data

As with most automotive requirements, TISAX is customer-driven. The OEMs — the major German carmakers and many others worldwide — and the larger Tier 1s require their partners to hold a valid TISAX label before they will share confidential specifications, designs, or personal data. If a customer has asked you for TISAX, or you want to win work with one who will, this is the standard you need. It is not a legal requirement, but for the automotive supply chain it is effectively a condition of doing business.

What TISAX requires

TISAX assesses you against the VDA ISA catalogue, and the scope depends on what information you handle. You choose one or more assessment objectives, the most common being information security, protection of prototypes, and data protection (personal data). Each objective comes with its own set of requirements.

The depth of the assessment is set by an assessment level (AL), which is driven by how sensitive the information is:

  • AL1 — a self-assessment, generally used internally and not the level customers rely on for high-value data
  • AL2 — the assessment provider reviews your self-assessment and evidence, usually with a remote or plausibility check; typical for information with a high protection need
  • AL3 — a comprehensive, mostly on-site assessment with interviews and direct verification; typical for very high protection needs, such as prototype protection

Underneath, the VDA ISA asks for the things a real information-security management system needs: a security policy owned by leadership, a working risk-management process, access control, supplier and third-party security, incident handling, business continuity, physical security, and — where prototypes are in scope — strict controls over secure areas, visitors, and the movement of pre-release parts. The AL2 and AL3 assessments must be carried out by a TISAX audit provider accredited by ENX. The right depth for each control should match your risk, not a generic checklist.

Why get TISAX assessed

The first reason is access, plain and simple. Without a valid TISAX label you generally cannot receive the confidential data or prototypes an OEM program depends on — which means you cannot bid, and you cannot deliver. With it, you become a trusted, findable partner in a supply chain that runs on long, stable relationships.

The second reason is efficiency. Before TISAX, every carmaker audited suppliers separately and suppliers filled in endless one-off security questionnaires. TISAX replaces that with one assessment, shared many times. You do the work once and release your result to each customer who needs it, which shortens qualification and frees your team from repeat audits.

The third reason is genuine risk reduction. Going through VDA ISA surfaces the gaps you did not know you had — unmanaged suppliers, weak access control, no tested incident plan, prototype areas anyone can walk into — and forces them to be owned and closed. In an industry where a single leaked design or stolen prototype can cost a program, that discipline protects your customer's secrets and your own reputation at the same time.

How QSE gets you assessed

We bring more than 30 years of building information-security and quality systems, with 900+ organizations certified and a 100% first-time pass rate. Our 10-Step Approach turns TISAX from an intimidating catalogue into a clear, week-by-week path to a valid label.

We start by pinning down the right scope, assessment objectives, and assessment level for what your customer actually needs — getting this wrong is one of the most expensive mistakes in TISAX, so we settle it first. Then we run a gap assessment against the current VDA ISA, build a right-sized security system, and facilitate the risk work with your team so the decisions are genuinely yours.

Our documentation is deliberately lean: a single-level system, typically under 200 pages, written for the people who use it rather than to impress an assessor. We help you implement the controls, train your staff, and run internal checks and a management review before the assessment. Then we support you through the assessment with your ENX-accredited audit provider and the sharing of your result on the exchange platform. A typical TISAX project runs about 5 to 10 months, depending on your size, scope, and starting maturity — and you finish owning a system your team can actually run.

Common pitfalls we help you avoid

  • Choosing the wrong scope or assessment level, then finding it does not satisfy the customer who asked — an expensive way to learn
  • Missing the prototype protection objective when your customer expects it, so your label does not cover the data they need to share
  • Buying a template pack and calling it a security system — assessors spot generic documentation instantly and it will not reflect your real risks
  • Treating TISAX as an IT-only project, when it covers people, suppliers, and physical security and needs leadership ownership
  • A risk assessment nobody on your team can explain, which falls apart the moment the assessor probes it
  • Weak physical controls over prototype and secure areas — a frequent finding at AL3
  • Over-documenting into thick manuals no one reads, which become findings rather than strengths
  • Forgetting the label expires — treating it as a one-off scramble instead of a system you maintain toward the next assessment