# TISAX and Penetration Testing: What Is Actually Required

Does TISAX require a penetration test? What the VDA ISA asks for, how assessment levels AL2 and AL3 differ, and where a pentest fits for automotive suppliers.

Source: https://zyberum.com/insights/tisax-and-penetration-testing · Updated: 2026-10-07

TISAX does not list "run a penetration test" as a universal requirement, and that is the honest starting point. **TISAX** (Trusted Information Security Assessment Exchange), operated by the ENX Association, is a mechanism for automotive suppliers and partners to assess their information security against the **VDA ISA** catalogue and share the result. Whether a penetration test is needed depends on what you protect, which VDA ISA controls apply and at which assessment level you are assessed. This article sets out where testing actually fits, so you neither skip it when it is expected nor buy it when it is not.

## What TISAX assesses

TISAX measures an information security management system against the VDA ISA (Information Security Assessment), a control catalogue maintained by the VDA and administered through ENX. The controls are rated on a maturity scale, and the target for assessed controls is a defined maturity level. TISAX itself is **not a certificate**: it is an assessment whose result is exchanged between participants over the ENX platform. We say this plainly because Zyberum is not an assessment provider and issues no TISAX labels. What we do is the security testing and advice behind the evidence.

## Where a penetration test fits

A penetration test is not a checkbox with the word "TISAX" on it. It earns its place through specific VDA ISA expectations:

- **Vulnerability identification.** The ISA expects you to identify vulnerabilities in your systems and, for the critical ones, to assess and act on them. A penetration test is a direct, documented way to do that and to show you did.
- **Effectiveness of controls.** Controls have to be shown to work, not just to exist on paper. A test produces that evidence for the systems in scope.
- **Secure development, where it applies.** If your information security protection need extends to the products or software you build, testing supports the controls around development and the handling of findings.

So the question is not "does TISAX require a pentest" in the abstract. It is: given your protection need and the systems in your scope, does the assessor expect to see that vulnerabilities are found and controls verified? Often the answer is yes, and a test is the cleanest way to provide it.

## Assessment levels and depth

The assessment level drives how deeply the assessor verifies, and therefore how much practical testing evidence is expected.

| Aspect | AL2 | AL3 |
|---|---|---|
| Typical method | Remote assessment of evidence | On-site assessment |
| Depth | Evidence-based review of the controls | Deeper, practical verification of controls |
| Used for | Normal protection need | High protection need |
| Testing evidence | Supports the review | Expected to show controls working in practice |

Both levels assess the same VDA ISA controls. The higher the protection need, the more an assessor wants to see the controls demonstrably effective rather than merely described, which is exactly where a penetration test and its report carry weight.

## How this connects to the rest of automotive security

For suppliers, TISAX rarely stands alone. The same organisation usually carries obligations under **ISO/SAE 21434** and **UN R155** for the products themselves, and increasingly under the Cyber Resilience Act for connected components. A single testing programme can feed several of these: a pentest and its evidence support the TISAX assessment of your IT, while product-side testing and a TARA support the 21434 and R155 work. Planning them together avoids paying twice for overlapping evidence.

## What to do

1. **Confirm your scope and protection need**, since they decide the assessment level and what evidence the assessor expects.
2. **Map the VDA ISA controls that imply testing**, in particular vulnerability identification and effectiveness verification.
3. **Test the systems in scope** and keep the report as evidence.
4. **Reuse the evidence** across your 21434, R155 and CRA obligations where the same systems are involved.

Zyberum tests the IT, cloud and product systems that sit behind a TISAX assessment, always under written authorisation, and advises automotive suppliers on ISO/SAE 21434 and UN R155. We do not perform the assessment or issue the label. See [automotive security](/automotive-security) or book a [free call](/contact?meeting=intro).

## FAQ

**Does TISAX require a penetration test?**

Not as a universal, named line item for every participant. TISAX assesses an information security management system against the VDA ISA. A penetration test becomes relevant where the ISA asks for vulnerability identification and for verifying the effectiveness of controls, and an on-site assessment at the higher assessment level includes practical verification of systems.

**What is the difference between AL2 and AL3?**

Both assess the same VDA ISA controls. The difference is depth of verification. AL2 is typically a remote assessment based on evidence. AL3 is an on-site assessment with deeper, practical verification, used for the highest protection needs. The higher the protection need, the more the assessor expects to see controls actually working, which is where testing evidence matters.

**Is TISAX a certification?**

No. TISAX is an assessment and exchange mechanism operated by the ENX Association, not a certificate. Results are shared between participants over the ENX platform. Zyberum is not an assessment provider and does not issue TISAX labels; we provide the security testing and the evidence that supports an assessment.

## Sources

- [ENX Association: TISAX](https://enx.com/en-US/TISAX/)
- [ENX Association: TISAX downloads (VDA ISA)](https://www.enx.com/en-us/tisax/downloads/)
- [VDA: Automotive industry information security (VDA ISA)](https://www.vda.de/en/topics/digitalization/information-security)

## Related

- [TISAX](https://zyberum.com/glossary/tisax)
- [Penetration test](https://zyberum.com/glossary/penetration-test)
- [Cybersecurity for Automotive Suppliers: UN R155, ISO/SAE 21434 and the CRA](https://zyberum.com/for/automotive-suppliers)
- [How Often Should You Pentest? Frequencies by System and Rule](https://zyberum.com/insights/how-often-to-pentest)
- [ISO/SAE 21434 that survives the audit and the attacker.](https://zyberum.com/iso-21434-consulting)
- [We break in. You get the proof and the fix.](https://zyberum.com/penetration-testing)

---
Zyberum GmbH. Canonical page: https://zyberum.com/insights/tisax-and-penetration-testing
