Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

How to Register for TISAX: A Step-by-Step Walkthrough

August 11, 2026
hero-how-to-register-for-tisax-1.png

To register for TISAX, you start on the ENX platform, not with an auditor. Registration is the first of TISAX’s three stages: Registration, Assessment, and Exchange. It happens entirely inside the ENX portal, the online system ENX Association runs for the whole process.

You do not contact an audit provider yet. You are not filling out the VDA ISA questionnaire yet. Registration is administrative: an account, a participant type, accepted terms, and a defined scope. Get those four things right and the rest of the process runs smoothly.

If a customer just told you that you need TISAX and you are not sure what that even means, start with our overview of TISAX and the VDA ISA standard first. And if you want a sense of where your company actually stands before you touch the ENX portal, our free VDA ISA self-assessment checklist will flag your weak chapters in advance, so registration isn’t the moment you discover a gap.

How to Register for TISAX

Here is the sequence, in order. Each step happens on the ENX portal.

TISAX Registration Steps
  1. Create your ENX portal account. This is a standard account signup: company name, contact details, and billing information for the ENX Association fee covered later in this guide.
  2. Register as a TISAX participant. You tell ENX what kind of participant your company is in the exchange, active or passive. More below.
  3. Accept the ENX terms and conditions. A short legal step. You cannot move forward without it.
  4. Register your TISAX Assessment Scope. You define which locations and which parts of your business the assessment will cover. More below.

Step 1: Create Your ENX Portal Account

Every TISAX registration begins with a portal account on the ENX platform. This is the same platform that later hosts your self-assessment, your audit provider’s report, and your result-sharing permissions. One account carries you through the entire three-year cycle.

Setting it up is straightforward. You provide standard company information and a billing contact, since the ENX Association registration fee (covered below) gets invoiced through this account. There is no technical prerequisite and no VDA ISA knowledge required at this stage.

Keep the login with whoever owns compliance long-term, not a single IT contractor or outside consultant. You will come back to this account every time you renew, add a location, or share results with a new business partner.

Step 2: Register as a TISAX Participant

Once your account exists, you register as a TISAX participant. In ENX’s terminology, a participant is any company that exchanges TISAX assessment results with other companies in the system. That covers almost every business touching the process, but not in the same role.

Active TISAX participants get assessed and receive a label; passive participants only receive results without being assessed themselves.

There are two participant types:

  • Active participants are suppliers being assessed. If a customer asked you to get TISAX, you are an active participant. You complete the self-assessment, get audited, and receive a label.
  • Passive participants are companies that only receive results. An OEM or Tier 1 buyer that requests your TISAX label but is not itself being assessed registers as passive.

Most readers of this guide are registering as active participants. You pick this designation during registration, and it determines which parts of the ENX portal you interact with afterward. A supplier that later starts requesting labels from its own subcontractors can register as both.

Step 3: Accept the ENX Terms and Conditions

Next, you accept ENX’s terms and conditions for using the platform and participating in the exchange. This is a standard legal acknowledgment, not a negotiation. You cannot register a participant scope or select an audit provider until you accept it.

Read it once, but do not expect anything unusual. It covers how ENX operates the platform, how data moves between participants, and what obligations come with holding an account. Most companies clear this step in a few minutes.

Step 4: Register Your TISAX Assessment Scope

This is the step that actually shapes your assessment. Your TISAX Assessment Scope defines which parts of your company the assessment covers, which physical locations, and which business units handle the information your customer cares about. The audit provider uses your registered scope to build its task description and estimate its effort. Get the scope wrong and the assessment will not actually satisfy your customer’s request.

Do not overthink this step. The ENX handbook is direct about it: early scope decisions carry little risk, and an audit provider can still conduct the assessment even if the scope needed a small adjustment later. You are defining a starting point, not locking in a permanent structure.

Companies with more than one location face a real choice here: one combined scope, or several separate ones.

ApproachHow it worksBest for
Single scopeOne registration covers every included location; produces one report and one labelCompanies where every location handles the same kind of information and can meet the same objectives
Multiple scopesEach location or business unit gets its own registration and its own reportMulti-location companies where sites handle different information, or need different Assessment Levels

A single scope is simpler to administer. It produces one assessment and one label to manage. But every location inside that scope has to meet the same requirements, even if some sites handle far more sensitive information than others.

Multiple scopes cost more to manage. You are tracking several registrations, several reports, and possibly several renewal dates instead of one. In exchange, each location only gets held to the requirements it actually needs.

If you are not sure which structure fits, this is a reasonable question to bring to your chosen audit provider once you reach that step, or to raise with LeadingIT if you want a second opinion on how your infrastructure maps to VDA ISA chapters before you commit.

Step 5: Select Your Assessment Objective(s)

The last piece of registration is choosing your assessment objectives. Your customer decides these, not you. They come from what your company handles for that customer, information or prototype material. They also come from how sensitive it is: normal, high, or very high protection need.

Each objective maps to an Assessment Level, AL 1, AL 2, or AL 3. Higher levels bring more verification: interviews, evidence review, sometimes an on-site visit. Our guide to TISAX Assessment Levels breaks down what each level actually requires. It also shows how your customer’s request maps to one of them.

A rough pattern, based on how the VDA ISA structures its objectives:

Objective typeTypical protection needTypical Assessment Level
Confidential information handlingNormal to highAL 2
Strictly confidential information / prototype protectionVery highAL 3
Data handling as a GDPR processorDepends on the data involvedVaries by objective

Treat this as orientation, not a guarantee. Your actual objective and level come from your customer’s request, and your audit provider confirms it once you engage them. If you’re not sure what your customer is asking for, ask them before you select an objective in the portal. A wrong guess here means a scope mismatch later.

What TISAX Registration Costs

Registration is not free. ENX Association bills a mandatory fee, set by its TISAX Participation Price List. That fee is separate from whatever your audit provider charges for the assessment itself, and it goes to the billing contact you set up in Step 1.

A few things worth knowing about how it works:

TISAX Registration Cost Basics
  • Calculated per location included in your registered scope.
  • Due once you submit your registration, whether or not you go on to complete the assessment.
  • One-time for the full validity period of your resulting assessment. There’s no recurring annual charge.
  • Registering 20 or more locations? Ask ENX Association about its Participation Based Charges pricing model instead of the standard per-location fee.

LeadingIT doesn’t set or quote this fee, and we won’t estimate one for you here. ENX publishes exact figures in its own price list, and its registration team (tisax@enx.com) can walk you through the PBC option if your company spans many sites.

How Long Registration Takes

Once you submit, ENX Association reviews what you entered before issuing anything. Most participants receive their Participant-ID within 3-5 days of that approval.

Most companies receive their Participant-ID within 3-5 days of ENX Association approving the registration.

That’s a short wait, and it changes how you should think about Step 4. Minor scope adjustments rarely cost you real time. You’re not restarting a long clock if you need to tweak something after you submit, you’re just waiting on another quick review pass.

What Happens After You Register

Once your Participant-ID arrives, registration itself is done. The next move is choosing an accredited third-party audit provider, since ENX does not assign one for you.

Wait times for audit providers vary by provider and by season, so pick one early rather than waiting until you feel ready. Our complete guide to the TISAX certification process walks through that entire stage, from selecting a provider through completing your self-assessment.

If you want to know what actually happens once an auditor is engaged, from the opening meeting to the interviews to the closing meeting, see our breakdown of what happens in a TISAX audit. Registration gets your Participant-ID. Everything after that is the audit provider’s process, not ENX’s.

See Where You Stand

Before you create your ENX portal account, take the free 2-minute TISAX Readiness Check. It tells you which VDA ISA chapters need work first, so registration isn’t the start of a scramble.

Take the free 2-minute TISAX Readiness Check

Frequently Asked Questions

ENX Association charges a mandatory registration fee, calculated per location in your scope. It’s separate from what your audit provider charges for the assessment itself. The fee is one-time for your assessment’s validity period, and exact amounts are set by ENX’s own price list, not published in the participant handbook.

Most companies receive their Participant-ID within 3-5 days after ENX Association approves the submission. The account creation, participant registration, and scope steps themselves are quick since they don’t require technical documentation. Most of the wait is ENX’s review time, not your data entry.

An active participant is a supplier being assessed and sharing results. Most companies reading this guide fall into that category. A passive participant only receives other companies’ results, typically an OEM or Tier 1 buyer requesting your label. You choose your type when you register as a participant.

No. Registration happens entirely on the ENX portal before you contact anyone. You create your account, register as a participant, accept the terms, and define your scope first. Only after that do you choose an accredited third-party audit provider.

Yes, and it’s considered low risk. ENX’s own participant handbook notes that an audit provider can still conduct the assessment even if your scope needed a small adjustment. You’re defining a starting point during registration, not a permanent structure.

No. TISAX is an industry-run assessment standard, not a government regulation. The obligation to get it comes from your contracts, since a growing number of OEMs and Tier 1 suppliers require a current TISAX label to keep doing business with them.

Ready to Build the Controls Your Auditor Will Check?

LeadingIT doesn’t perform TISAX audits or issue labels, that’s an accredited third-party’s job. What we do is build the technical foundation your auditor will actually test:

  • Identity and access management: unique user IDs, MFA, least-privilege access, encryption.
  • IT security and operations: patch management, change management, monitoring.
  • Detection and response: incident logging and documented response procedures.
  • Business continuity: disaster recovery planning, defined recovery targets, tested failover.

If you want help getting those controls in shape before your audit provider shows up, see our compliance-readiness IT services. Or book a call and we’ll walk through where your infrastructure stands today.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.