Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryComplianceAutomotive

TISAX

TISAX is the automotive industry information security assessment, run by ENX on the VDA ISA catalogue. Assessment levels, labels, validity and practical demands.

Updated This page as Markdown

In short

TISAX (Trusted Information Security Assessment Exchange) is the assessment and exchange mechanism for information security in the automotive supply chain. ENX Association operates it on behalf of the VDA. Accredited audit providers assess a company against the VDA ISA catalogue; the result is a set of TISAX labels valid for three years, shared with OEMs and partners through the ENX portal instead of separate audits by every customer.

What is TISAX?

TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry’s mechanism for assessing and sharing the information security maturity of suppliers and service providers. ENX Association operates it on behalf of the VDA, the German Association of the Automotive Industry. A company registers as a participant, defines the scope (usually its locations), chooses assessment objectives, and is assessed by an ENX-accredited audit provider against the VDA ISA catalogue. The result is a set of TISAX labels that the company releases to its customers in the ENX portal.

The point is one assessment for many partners. Before TISAX every OEM audited each supplier separately; now an OEM checks the labels in the portal. Labels are valid for three years.

Where is it defined?

The requirements are the VDA ISA (Information Security Assessment) catalogue, published by the VDA and currently in its major version 6. It is built on the controls of ISO/IEC 27001 and 27002 and adds automotive-specific modules for prototype protection and for data protection in the role of a processor. Each control is rated on a maturity scale from 0 to 5; the target maturity is 3, and shortfalls become findings with a corrective action plan.

The process, the assessment levels and the labels are defined in the TISAX Participant Handbook from ENX. Assessment level 2 (AL2) is a plausibility check of the self-assessment with evidence, typically remote. Assessment level 3 (AL3) adds an on-site assessment with interviews and inspection and is required for very high protection needs and for prototype protection. Which level you need depends on the assessment objectives your customers ask for.

What it means in practice

TISAX assesses how a company protects the information its customers entrust to it: drawings, specifications, prototypes, personal data. It does not assess the cybersecurity of the product the company builds. That is the job of ISO/SAE 21434 and UN R155, and suppliers often need both.

The findings that cost suppliers the most time during preparation are the practical ones:

  • Scope and locations. Development partners work from home offices and external test benches that are not part of the defined scope but hold OEM data.
  • Prototype handling. Test vehicles and parts in workshops without camera rules, access control or disguised transport, which the prototype protection module checks in detail.
  • Development environments. Build servers, repositories and test infrastructure with OEM data, reachable with shared accounts or from the office network without segmentation. A penetration test of this environment is the fastest way to find out what an assessor will later ask about.
  • Supplier and remote access. Sub-suppliers and remote maintenance with standing VPN access and no logging.

Zyberum prepares companies for TISAX with gap analyses against the VDA ISA catalogue, penetration tests of the systems in scope and the technical hardening that follows. We are not an audit provider and do not issue labels.

Common misunderstandings

“TISAX certified” is a phrase that does not exist in the scheme; the correct wording is that a company holds TISAX labels for a defined scope. An ISO/IEC 27001 certificate does not replace an assessment. TISAX does not cover product cybersecurity, functional safety or the Cyber Resilience Act, even though OEMs increasingly ask for all of them in the same supplier questionnaire.

FAQ

Frequently asked questions

Is TISAX a certificate?

No. A TISAX assessment ends in labels and an assessment result that you share with partners via the ENX portal. There is no certificate in the sense of ISO/IEC 27001, and ENX asks participants not to call it one. Customers check the labels and the assessment level in the portal.

Does an ISO/IEC 27001 certificate replace TISAX?

No. The VDA ISA catalogue builds on ISO/IEC 27001 and 27002 controls, so a certified ISMS gives you a strong start, but TISAX adds automotive-specific requirements, in particular prototype protection and data protection, and it requires an assessment by an ENX-accredited audit provider. OEMs ask for TISAX labels, not for the ISO certificate.

Where does a penetration test fit into TISAX?

The VDA ISA catalogue requires vulnerability management, secure development and regular testing of systems. A penetration test is the usual evidence that these controls work, especially for internet-facing systems and development environments holding OEM data. Zyberum delivers the tests and the technical preparation; the assessment itself is done by an audit provider.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab