Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The TISAX Certification Process: How It Actually Works, Step by Step

August 11, 2026
hero-tisax-certification-process-1.png

The TISAX certification process runs through three stages: registration, self-assessment, and a third-party audit. A customer asked you for a TISAX label. Now you need the real sequence, not marketing copy.

Here’s what you’ll get from this guide. What information you hand over at registration. How an honest self-assessment saves you time later. How to pick an audit provider before your customer’s deadline forces a rushed choice.

TISAX is not a government program. It’s an industry-run standard built by the automotive sector. Skipping steps rarely saves time; it just moves the delay to a worse moment. Here’s the process, stage by stage.

The Three-Stage TISAX Process

TISAX Three-Stage Process

TISAX, short for Trusted Information Security Assessment Exchange, runs through three linked stages on the ENX platform. First, you register and define your assessment scope. Second, you self-assess against the VDA ISA catalogue and undergo a third-party audit at the Assessment Level your customer requires. Third, you exchange results, choosing exactly which business partners can see them. Each stage depends on the one before it.

Step 1: Register on the ENX Portal

Registration happens on the ENX Association portal, separate from the assessment itself. You create an account, then register your company as a TISAX participant.

Two participant types exist. Active participants are suppliers being assessed who share results. Passive participants are business partners who only receive results. Most readers of this guide are registering as active participants.

ENX Registration Steps

Registration follows a short sequence:

  1. Create your ENX portal account and accept the platform’s terms and conditions.
  2. Register as a TISAX participant (active, if you’re the one being assessed).
  3. Define at least one TISAX Assessment Scope covering the relevant locations and business units.
  4. Submit the registration for ENX Association review.
  5. Receive your Participant-ID once ENX approves the registration, typically within 3-5 days.

Your customer’s request drives your scope, not the other way around. If they need confidential engineering data protected at one facility, your scope covers that facility and that objective. It doesn’t need to cover your whole company.

Registering more than one location? You have two options:

  • One combined scope. Produces a single report and label, but every included location has to meet the same objectives.
  • Separate scopes per location. Lets each location target different objectives, at the cost of managing more registrations.

Don’t overthink the first pass. ENX’s own guidance is direct about how registration and scope work: early scope decisions are low-risk, and an audit provider can still work from a slightly different scope than the one you first registered.

Registration also carries a mandatory fee from ENX Association, on top of whatever your audit provider charges. It’s billed per location in your scope, once, for the assessment’s validity period, not annually. ENX offers a different pricing model on request.

Step 2: Self-Assess Against the VDA ISA Catalogue

Once you’re registered, you self-assess against the VDA ISA (Information Security Assessment) catalogue. This is the requirements list every TISAX audit is scored against.

Every objective gets scored on a six-point maturity scale:

LevelNameWhat It Means
0IncompleteNo suitable process exists or is followed
1PerformedAn informal process exists, with some evidence, but isn’t documented
2ManagedA documented process is followed, with implementation evidence
3EstablishedA standard process is integrated into your management system
4PredictableThe process is measured and controlled
5OptimizingThe process improves continuously based on business goals

Every MUST requirement in your scope needs a consistent Maturity Level 3 or higher to pass, not just documentation on paper.

Here’s why self-assessing honestly matters. If you inflate your own scores, your auditor finds the gap anyway, during the real audit. Now you’re remediating on a deadline, with your customer waiting.

Self-assess honestly first, and you find the same gaps on your own schedule instead. Work through the VDA ISA self-assessment checklist before you contact an audit provider. Fixing a weak access policy in week one is easier than explaining it to an auditor in week six.

Step 3: Choose an Accredited Audit Provider

You cannot self-certify TISAX. An accredited third-party audit provider has to verify your self-assessment, at a rigor level matched to what your customer requires.

Start this step early. ENX Association doesn’t publish standard wait times for audit providers, and availability varies by provider. Waiting until your self-assessment is done to start shopping for an auditor is a common way to blow a customer deadline.

Which Assessment Level (AL) you need depends on your customer’s request, not your preference:

LevelWho VerifiesWhat Happens
AL 1No independent checkYou complete the questionnaire; an auditor confirms it’s filled out, not that it’s accurate. Not accepted for exchange within TISAX.
AL 2Remote plausibility checkAn auditor reviews your evidence and interviews your security lead, usually by web conference.
AL 3Full on-site auditAn auditor examines documents, interviews process owners, and observes actual conditions and practices on site.

Higher levels satisfy lower ones automatically. An AL 3 audit covers an AL 2 request too.

Confirm your required level before you contact providers. If you’re unsure which level your customer’s request maps to, the assessment levels breakdown walks through how AL1, AL2, and AL3 map to protection needs like confidential information handling, strictly confidential data, and prototype protection.

New to TISAX fundamentals? See our overview of what TISAX and the VDA ISA standard are first. It covers what a label actually certifies. From here, the process moves into the provider’s hands.

Step 4: The Audit Itself

Every TISAX audit opens the same way, regardless of level. Your audit provider holds a formal opening meeting to confirm scope and logistics. It closes the same way too, with a formal closing meeting to walk through findings.

Comparison matrix contrasting the AL 2 remote plausibility check, which needs no site visit, against the AL 3 full on-site audit with unplanned interviews.

What happens in between depends on your Assessment Level.

At AL 2, your auditor performs a plausibility check, usually over web conference:

  • Reviews your self-assessment against the evidence you provide.
  • Interviews whoever owns information security at your company.
  • Confirms your documented answers match reality, without visiting your site.

At AL 3, the check is far more hands-on:

  • Examines documents and supporting evidence in detail.
  • Holds planned interviews with the people who own each process.
  • Observes actual conditions and daily practice on site, not just paperwork.
  • Conducts unplanned interviews too, catching gaps between what’s documented and what people actually do.

ENX Association won’t give you a standard timeline. Its own handbook is direct about that. It says predicting assessment duration reliably just isn’t possible. Scope, Assessment Level, and your provider’s schedule all move that number.

Pass the audit, and your provider issues the official assessment report. Your TISAX label becomes visible to your chosen business partners on the ENX platform shortly after.

What Happens When the Auditor Finds a Gap

Not every requirement carries the same weight. The VDA ISA splits them into two types.

Requirement TypeDefinitionIf You Fall Short
MUSTMandatory; needs Maturity Level 3 or higherMajor Non-Conformity
SHOULDRecommended, not mandatoryMinor Non-Conformity (if it appears at all)

A Minor Non-Conformity gets documented. It doesn’t block your label by itself.

A Major Non-Conformity is different. It has to be remediated before your provider can issue a label. Sourced guidance points to a remediation window of up to about 9 months.

An unresolved Major Non-Conformity on a MUST requirement blocks your TISAX label from being issued at all.

Here’s the practical read. A gap found during the formal audit costs you a remediation cycle. That cycle runs on your customer’s clock. The same gap, caught during your own honest self-assessment in Step 2, costs a normal work item instead. That happens on your own clock. That’s the whole argument for not rushing self-assessment.

Step 5: Exchange Your Results

Passing the audit doesn’t automatically hand your results to anyone. Sharing is a separate, deliberate step you control on the ENX platform.

You decide, partner by partner, exactly what each one can see. A Tier 1 customer might get full visibility into your assessment. A different partner might see only that you hold a valid label, not the underlying detail.

One thing to know before you grant access: sharing permissions can’t be revoked once given. Decide deliberately, not by default, about which partners get which level of detail.

Labels and the Three-Year Validity Clock

A passed assessment produces one or more TISAX labels. Each label corresponds to one objective you were assessed against:

TISAX label objectives include information security, prototype protection, data protection, or a combination of these
  • Information security
  • Prototype protection
  • Data protection
  • Or some combination of these

Those labels last three years. When the clock runs out, there’s no shortcut. You repeat the full three-stage process: register again, self-assess again, get audited again.

The payoff for going through it once shows up here. One valid label, shared with every partner who asks, beats running a separate audit for each customer. That’s the efficiency TISAX is actually built around.

See Where You Stand

Before you register for TISAX, take the free 2-minute TISAX Readiness Check. See which VDA ISA chapters your organization is weakest on so you walk into registration and self-assessment with a plan, not a guess.

Take the free 2-minute TISAX Readiness Check

Frequently Asked Questions

How long does the TISAX certification process take?

ENX Association doesn’t publish a standard timeline, and says publicly it can’t forecast one reliably. Your total time depends on your scope, your Assessment Level, and your chosen audit provider’s availability. Starting your audit provider search early, before your self-assessment is finished, is the best way to avoid unnecessary delay.

How much does TISAX certification cost?

ENX Association charges a mandatory registration fee, billed per location in your scope, due once for the assessment’s validity period. Your accredited audit provider charges separately for the audit itself, and that cost varies by provider and scope. Exact dollar figures come from ENX’s published price list, not from this guide.<details> <summary>Can I self-certify for TISAX without a third-party audit?</summary> <p>Not for anything your customer will accept. AL 1 is self-assessment only, and an auditor merely confirms you completed the questionnaire, not that it’s accurate. Those AL 1 results aren’t accepted for exchange within TISAX itself. Any label your business partners will recognize requires third-party verification at AL 2 or AL 3.

TISAX adds automotive-specific objectives, like prototype protection, plus a mechanism for sharing results across partners. It’s also contractual, not a government mandate like some other frameworks.</p> </details>

What happens if I fail a TISAX audit?

A gap on a MUST requirement becomes a Major Non-Conformity, and it blocks your label until it’s fixed. Sourced guidance points to a remediation window of up to about 9 months. A gap on a SHOULD requirement is a Minor Non-Conformity, which gets documented but doesn’t block the label by itself. Catching gaps yourself during self-assessment, before the formal audit, avoids this timeline pressure entirely.

How long is a TISAX label valid?

A TISAX label is valid for three years from the date it’s issued. When it expires, there’s no partial renewal. You repeat the full process: register, self-assess, and get audited again.

Who needs a TISAX label?

Anyone in the automotive supply chain whose OEM or Tier 1 customer requires one. That includes parts suppliers, engineering and design service providers, prototype handlers, IT and software vendors, and logistics providers serving automotive clients. There’s no independent legal requirement. The obligation comes from your contract, because more OEMs now write a current TISAX label into supplier requirements.

Where LeadingIT Fits In

TISAX itself is audited by an ENX-accredited third party, not by LeadingIT. We don’t perform the audit or issue labels.

What we do is get the systems underneath it ready, the technical foundation VDA ISA actually scores:

  • Access controls and identity management
  • Patch and change management
  • Incident detection and response
  • Tested backups and disaster recovery

See LeadingIT’s compliance-readiness IT services for that side of the work. Book a call to talk through your scope, or contact us with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.