The TISAX Certification Process: How It Actually Works, Step by Step
The TISAX certification process runs through three stages: registration, self-assessment, and a third-party audit. A customer asked you for a TISAX label. Now you need the real sequence, not marketing copy.
Here’s what you’ll get from this guide. What information you hand over at registration. How an honest self-assessment saves you time later. How to pick an audit provider before your customer’s deadline forces a rushed choice.
TISAX is not a government program. It’s an industry-run standard built by the automotive sector. Skipping steps rarely saves time; it just moves the delay to a worse moment. Here’s the process, stage by stage.
The Three-Stage TISAX Process

TISAX, short for Trusted Information Security Assessment Exchange, runs through three linked stages on the ENX platform. First, you register and define your assessment scope. Second, you self-assess against the VDA ISA catalogue and undergo a third-party audit at the Assessment Level your customer requires. Third, you exchange results, choosing exactly which business partners can see them. Each stage depends on the one before it.
Step 1: Register on the ENX Portal
Registration happens on the ENX Association portal, separate from the assessment itself. You create an account, then register your company as a TISAX participant.
Two participant types exist. Active participants are suppliers being assessed who share results. Passive participants are business partners who only receive results. Most readers of this guide are registering as active participants.

Registration follows a short sequence:
- Create your ENX portal account and accept the platform’s terms and conditions.
- Register as a TISAX participant (active, if you’re the one being assessed).
- Define at least one TISAX Assessment Scope covering the relevant locations and business units.
- Submit the registration for ENX Association review.
- Receive your Participant-ID once ENX approves the registration, typically within 3-5 days.
Your customer’s request drives your scope, not the other way around. If they need confidential engineering data protected at one facility, your scope covers that facility and that objective. It doesn’t need to cover your whole company.
Registering more than one location? You have two options:
- One combined scope. Produces a single report and label, but every included location has to meet the same objectives.
- Separate scopes per location. Lets each location target different objectives, at the cost of managing more registrations.
Don’t overthink the first pass. ENX’s own guidance is direct about how registration and scope work: early scope decisions are low-risk, and an audit provider can still work from a slightly different scope than the one you first registered.
Registration also carries a mandatory fee from ENX Association, on top of whatever your audit provider charges. It’s billed per location in your scope, once, for the assessment’s validity period, not annually. ENX offers a different pricing model on request.
Step 2: Self-Assess Against the VDA ISA Catalogue
Once you’re registered, you self-assess against the VDA ISA (Information Security Assessment) catalogue. This is the requirements list every TISAX audit is scored against.
Every objective gets scored on a six-point maturity scale:
| Level | Name | What It Means |
|---|---|---|
| 0 | Incomplete | No suitable process exists or is followed |
| 1 | Performed | An informal process exists, with some evidence, but isn’t documented |
| 2 | Managed | A documented process is followed, with implementation evidence |
| 3 | Established | A standard process is integrated into your management system |
| 4 | Predictable | The process is measured and controlled |
| 5 | Optimizing | The process improves continuously based on business goals |
Every MUST requirement in your scope needs a consistent Maturity Level 3 or higher to pass, not just documentation on paper.
Here’s why self-assessing honestly matters. If you inflate your own scores, your auditor finds the gap anyway, during the real audit. Now you’re remediating on a deadline, with your customer waiting.
Self-assess honestly first, and you find the same gaps on your own schedule instead. Work through the VDA ISA self-assessment checklist before you contact an audit provider. Fixing a weak access policy in week one is easier than explaining it to an auditor in week six.
Step 3: Choose an Accredited Audit Provider
You cannot self-certify TISAX. An accredited third-party audit provider has to verify your self-assessment, at a rigor level matched to what your customer requires.
Start this step early. ENX Association doesn’t publish standard wait times for audit providers, and availability varies by provider. Waiting until your self-assessment is done to start shopping for an auditor is a common way to blow a customer deadline.
Which Assessment Level (AL) you need depends on your customer’s request, not your preference:
| Level | Who Verifies | What Happens |
|---|---|---|
| AL 1 | No independent check | You complete the questionnaire; an auditor confirms it’s filled out, not that it’s accurate. Not accepted for exchange within TISAX. |
| AL 2 | Remote plausibility check | An auditor reviews your evidence and interviews your security lead, usually by web conference. |
| AL 3 | Full on-site audit | An auditor examines documents, interviews process owners, and observes actual conditions and practices on site. |
Higher levels satisfy lower ones automatically. An AL 3 audit covers an AL 2 request too.
Confirm your required level before you contact providers. If you’re unsure which level your customer’s request maps to, the assessment levels breakdown walks through how AL1, AL2, and AL3 map to protection needs like confidential information handling, strictly confidential data, and prototype protection.
New to TISAX fundamentals? See our overview of what TISAX and the VDA ISA standard are first. It covers what a label actually certifies. From here, the process moves into the provider’s hands.
Step 4: The Audit Itself
Every TISAX audit opens the same way, regardless of level. Your audit provider holds a formal opening meeting to confirm scope and logistics. It closes the same way too, with a formal closing meeting to walk through findings.

What happens in between depends on your Assessment Level.
At AL 2, your auditor performs a plausibility check, usually over web conference:
- Reviews your self-assessment against the evidence you provide.
- Interviews whoever owns information security at your company.
- Confirms your documented answers match reality, without visiting your site.
At AL 3, the check is far more hands-on:
- Examines documents and supporting evidence in detail.
- Holds planned interviews with the people who own each process.
- Observes actual conditions and daily practice on site, not just paperwork.
- Conducts unplanned interviews too, catching gaps between what’s documented and what people actually do.
ENX Association won’t give you a standard timeline. Its own handbook is direct about that. It says predicting assessment duration reliably just isn’t possible. Scope, Assessment Level, and your provider’s schedule all move that number.
Pass the audit, and your provider issues the official assessment report. Your TISAX label becomes visible to your chosen business partners on the ENX platform shortly after.
What Happens When the Auditor Finds a Gap
Not every requirement carries the same weight. The VDA ISA splits them into two types.
| Requirement Type | Definition | If You Fall Short |
|---|---|---|
| MUST | Mandatory; needs Maturity Level 3 or higher | Major Non-Conformity |
| SHOULD | Recommended, not mandatory | Minor Non-Conformity (if it appears at all) |
A Minor Non-Conformity gets documented. It doesn’t block your label by itself.
A Major Non-Conformity is different. It has to be remediated before your provider can issue a label. Sourced guidance points to a remediation window of up to about 9 months.
An unresolved Major Non-Conformity on a MUST requirement blocks your TISAX label from being issued at all.
Here’s the practical read. A gap found during the formal audit costs you a remediation cycle. That cycle runs on your customer’s clock. The same gap, caught during your own honest self-assessment in Step 2, costs a normal work item instead. That happens on your own clock. That’s the whole argument for not rushing self-assessment.
Step 5: Exchange Your Results
Passing the audit doesn’t automatically hand your results to anyone. Sharing is a separate, deliberate step you control on the ENX platform.
You decide, partner by partner, exactly what each one can see. A Tier 1 customer might get full visibility into your assessment. A different partner might see only that you hold a valid label, not the underlying detail.
One thing to know before you grant access: sharing permissions can’t be revoked once given. Decide deliberately, not by default, about which partners get which level of detail.
Labels and the Three-Year Validity Clock
A passed assessment produces one or more TISAX labels. Each label corresponds to one objective you were assessed against:

- Information security
- Prototype protection
- Data protection
- Or some combination of these
Those labels last three years. When the clock runs out, there’s no shortcut. You repeat the full three-stage process: register again, self-assess again, get audited again.
The payoff for going through it once shows up here. One valid label, shared with every partner who asks, beats running a separate audit for each customer. That’s the efficiency TISAX is actually built around.
See Where You Stand
Before you register for TISAX, take the free 2-minute TISAX Readiness Check. See which VDA ISA chapters your organization is weakest on so you walk into registration and self-assessment with a plan, not a guess.
Take the free 2-minute TISAX Readiness Check
Related Guides
- What Is TISAX? The VDA ISA Standard Explained for Automotive Suppliers
- TISAX Assessment Levels (AL1, AL2, AL3) and Maturity Levels Explained
- VDA ISA Checklist: How to Self-Assess Before Your TISAX Audit
Frequently Asked Questions
How long does the TISAX certification process take?
ENX Association doesn’t publish a standard timeline, and says publicly it can’t forecast one reliably. Your total time depends on your scope, your Assessment Level, and your chosen audit provider’s availability. Starting your audit provider search early, before your self-assessment is finished, is the best way to avoid unnecessary delay.
How much does TISAX certification cost?
ENX Association charges a mandatory registration fee, billed per location in your scope, due once for the assessment’s validity period. Your accredited audit provider charges separately for the audit itself, and that cost varies by provider and scope. Exact dollar figures come from ENX’s published price list, not from this guide.<details> <summary>Can I self-certify for TISAX without a third-party audit?</summary> <p>Not for anything your customer will accept. AL 1 is self-assessment only, and an auditor merely confirms you completed the questionnaire, not that it’s accurate. Those AL 1 results aren’t accepted for exchange within TISAX itself. Any label your business partners will recognize requires third-party verification at AL 2 or AL 3.
TISAX adds automotive-specific objectives, like prototype protection, plus a mechanism for sharing results across partners. It’s also contractual, not a government mandate like some other frameworks.</p> </details>
What happens if I fail a TISAX audit?
A gap on a MUST requirement becomes a Major Non-Conformity, and it blocks your label until it’s fixed. Sourced guidance points to a remediation window of up to about 9 months. A gap on a SHOULD requirement is a Minor Non-Conformity, which gets documented but doesn’t block the label by itself. Catching gaps yourself during self-assessment, before the formal audit, avoids this timeline pressure entirely.
How long is a TISAX label valid?
A TISAX label is valid for three years from the date it’s issued. When it expires, there’s no partial renewal. You repeat the full process: register, self-assess, and get audited again.
Who needs a TISAX label?
Anyone in the automotive supply chain whose OEM or Tier 1 customer requires one. That includes parts suppliers, engineering and design service providers, prototype handlers, IT and software vendors, and logistics providers serving automotive clients. There’s no independent legal requirement. The obligation comes from your contract, because more OEMs now write a current TISAX label into supplier requirements.
Where LeadingIT Fits In
TISAX itself is audited by an ENX-accredited third party, not by LeadingIT. We don’t perform the audit or issue labels.
What we do is get the systems underneath it ready, the technical foundation VDA ISA actually scores:
- Access controls and identity management
- Patch and change management
- Incident detection and response
- Tested backups and disaster recovery
See LeadingIT’s compliance-readiness IT services for that side of the work. Book a call to talk through your scope, or contact us with questions.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
