The Complete TISAX Compliance Guide for Automotive Suppliers
TISAX compliance means proving your security processes hit a consistent maturity level across the VDA ISA catalogue. It is not a certificate you buy off the shelf. It is a label you earn, chapter by chapter, through an accredited auditor’s review.
TISAX (Trusted Information Security Assessment Exchange) is the information security standard used across the European and global automotive industry. The VDA, Germany’s automotive trade association, created it. The ENX Association runs it day to day on the VDA’s behalf, accrediting the audit providers and keeping results consistent across auditors. If you need the ground-level definition first, our guide to what TISAX actually is covers that.
Here is the part that trips up a lot of suppliers: “compliant” does not mean you filled out a form once and moved on. It means your controls perform at a defined standard, and keep performing at that standard, for as long as your customer needs the label current. That distinction shapes everything below.
Why TISAX Lands on Your Desk
Nobody wakes up and decides to pursue TISAX for fun. It shows up because a customer requires it.
Specifically, an OEM or Tier 1 supplier writes a current TISAX label into a contract or RFQ as a condition of doing business. No label, no bid. Sometimes no renewal, either.
TISAX applies to a wide range of businesses in the supply chain, not just parts manufacturers. That list typically includes:
- Parts and component suppliers
- Engineering and design service providers
- Prototype and pre-series parts handlers
- IT and software vendors serving automotive clients
- Logistics providers
- Any subcontractor that stores or transmits an automotive partner’s confidential data or personal data covered by GDPR
Here is the important nuance: TISAX itself carries no government fine and no statutory penalty. It is not a law. The consequence is commercial, not legal. A supplier without a current label can lose a bid, lose a renewal, or get stuck on a remediation clock while a customer waits. That is why there is effectively no way around it if you want the business. The trigger is your customer’s contract, not a regulator’s mailbox.
The TISAX Compliance Journey, Step by Step
The path to a label runs through five stages on the ENX platform. For the full mechanics of each one, see our step-by-step TISAX certification process. Here is the journey at a glance.
| Stage | What Happens | Where to Go Deeper |
|---|---|---|
| 1. Registration | You create an ENX portal account, define the assessment objectives your customer requires, and register your assessment scope. | How to register for TISAX |
| 2. Self-Assessment | You complete the VDA ISA questionnaire yourself, rating your own controls against every objective in scope. | VDA ISA checklist |
| 3. Assessment Level | Your customer’s requirement, not your own preference, determines whether you need AL 1, AL 2, or AL 3 review. | Assessment level detail (covered separately) |
| 4. Third-Party Audit | An accredited auditor checks your evidence, interviews your team, and verifies your self-assessment holds up. | Audit walkthrough (covered separately) |
| 5. Result Exchange | You decide, partner by partner, who can see your results and at what level of detail. | — |
A few things worth flagging up front. Registration is low-stakes: the ENX handbook is explicit that a slightly imperfect early scope choice rarely causes problems, since an audit provider can still work with it. Sharing, on the other hand, is a one-way door. Once you grant a business partner visibility into your results, you cannot revoke it for that partner. Choose your audit provider early, too. Wait times vary, and a late start on that step is a common way this timeline slips.
What “Being Compliant” Actually Requires
This is where a lot of the confusion happens. Being TISAX compliant does not mean you have a policy binder somewhere. It means your controls score a specific way on a defined maturity scale, across every relevant chapter of the VDA ISA.
The VDA ISA is built on key aspects of ISO/IEC 27001 and organized into nine chapters:
| # | Chapter | Covers |
|---|---|---|
| 1 | IS Policies and Organization | Governance and security policy structure |
| 2 | Organizational Security | Roles, responsibilities, and oversight |
| 3 | Personnel Security | Hiring, training, and offboarding controls |
| 4 | Physical and Environmental Security | Facility access and environmental protection |
| 5 | Identity and Access Management | User IDs, MFA, least-privilege access |
| 6 | IT Security and Operations | Patching, change management, monitoring |
| 7 | Detection and Response to Security Incidents | Incident logging and response procedures |
| 8 | Business Continuity | Disaster recovery, RTO/RPO, tested failover |
| 9 | Compliance and Data Protection | Legal adherence and GDPR-aligned controls |
Every requirement in that catalogue gets scored on a six-point maturity scale, Level 0 through Level 5. The two levels that matter most for a first-time reader are these: Level 2 means a documented process exists with some evidence it runs. Level 3 means that process is standard and built into how the company actually operates, not just written down.
Every MUST requirement in the VDA ISA has to reach Maturity Level 3 or higher for the assessment to pass.
That last point is the one people miss. The catalogue splits requirements into MUST (mandatory) and SHOULD (recommended, not mandatory). A gap on a MUST requirement is a Major Non-Conformity, and it blocks your label until you fix it. A gap on a SHOULD requirement gets documented but does not block you on its own.
This also explains why a policy binder alone does not clear the bar. An auditor is not just checking that a document exists. They are checking whether the process behind it is actually consistent, repeatable, and part of daily operations, not something written up right before the audit. Before you get anywhere near an actual audit, running your own gap check against the VDA ISA checklist is the fastest way to find out where you are exposed.
Compliance Is Not a One-Time Event
A TISAX label does not last forever. Under the participant handbook, your results stay valid for three years from the day your audit provider issues them.

That window is not a grace period. The maturity level you proved on assessment day is the maturity level your customer expects you to hold every day after. An auditor is not checking back weekly, but your controls still need to run at Level 3 or higher on every MUST requirement, all three years.
When the three years are up, there is no shortcut. You repeat the same process: register, self-assess, get audited, exchange results again. Suppliers who treat the label as “done” often start renewal cold, scrambling to rebuild evidence they let lapse. Suppliers who keep their controls running day to day sail through it instead.
TISAX and the Standards You May Already Know
If your business already works toward other security frameworks, TISAX will feel familiar in places. The VDA ISA catalogue borrows heavily from the international standard ISO/IEC 27001.
That overlap matters if your company has already started, or completed, ISO 27001 work. Some of the same access control, incident response, and business continuity groundwork applies to both. It is not a one-for-one substitute, though, and the two labels serve different audiences for different reasons. If you are weighing the two side by side, our TISAX vs. ISO 27001 comparison breaks down where they overlap and where they diverge.
What Happens If You Don’t Maintain It
Let’s be direct about the stakes. TISAX carries no government fine. There is no regulator sending a penalty notice.
The real cost shows up in your customer relationship instead:
- A Major Non-Conformity on a MUST requirement blocks your label from being issued at all, until you fix it.
- A lapsed or missing label can knock you out of a bid, since OEMs and Tier 1 suppliers increasingly write a current label into contracts.
- A supplier that lets its label expire mid-relationship can find renewal terms suddenly on the table.
None of that is a legal penalty. All of it is a revenue problem. For a supplier that depends on automotive contracts, a missing label functions like a fine even without one being written anywhere.
The Technical Backbone This Actually Rests On
Here is the part a lot of overview guides skip. TISAX compliance is not really a paperwork exercise. It is a test of whether your everyday IT operations are solid.
Four areas do most of the heavy lifting, and they map directly to VDA ISA chapters you saw earlier in this guide:

- Access management. Unique user IDs, multifactor authentication, and least-privilege permissions, so only the right people touch the right data.
- Patch and change management. A consistent process for applying updates and controlling changes to production systems, not ad hoc fixes.
- Incident response. A documented, tested procedure for detecting and responding to a security incident, not something written the week before an audit.
- Backups and disaster recovery. Backups that are actually tested, with a defined recovery time and recovery point, not just a backup job that runs unattended.
Small and mid-size suppliers often have pieces of this already. The gap is usually consistency: a backup that has never been test-restored, an access list nobody has reviewed in a year, an incident plan that lives in someone’s head. Those gaps are exactly what an auditor is trained to find.
See Where You Stand
Not sure where your organization actually stands on the road to a TISAX label? Take the free 2-minute TISAX Readiness Check: see your maturity level today against the chapters that matter most, before you spend a dollar on registration or an audit.
Take the free 2-minute TISAX Readiness Check
Related Guides
- What Is TISAX? The VDA ISA Standard Explained for Automotive Suppliers
- How to Register for TISAX: A Step-by-Step Walkthrough
- The TISAX Certification Process: Step by Step
- TISAX Assessment Levels (AL1, AL2, AL3) and Maturity Levels Explained
- What Happens in a TISAX Audit: What to Expect
- VDA ISA Checklist: How to Self-Assess Before Your TISAX Audit
- TISAX vs ISO 27001: What’s the Difference?
Frequently Asked Questions
How long does a TISAX label last?
A TISAX label and the results behind it stay valid for three years from the date your audit provider issues them. After that, you repeat the full process: registration, self-assessment, audit, and result exchange. There is no partial renewal.
Is TISAX a legal requirement?
No. TISAX is not a government regulation or a law. It is an industry-run assessment standard, and the obligation to get a label comes from your contract with an OEM or Tier 1 customer, not from a regulator.
What happens if you fail a TISAX audit?
A gap on a mandatory MUST requirement becomes a Major Non-Conformity, which blocks your label until it is fixed. A gap on a recommended SHOULD requirement gets documented but does not block the label by itself.
How much does TISAX compliance cost?
Registration carries a fee set by ENX Association’s own price list, charged per location in your scope, separate from whatever your chosen audit provider charges for the assessment itself. Exact figures depend on your scope and are not published as a flat rate, so ask your audit provider for a quote based on your specific situation.
The United States ranks third globally by location count, behind Germany and China.</p> </details>
How is TISAX different from ISO 27001?
The VDA ISA catalogue that TISAX assessments use is built on key aspects of ISO/IEC 27001, so the two share some DNA. They are not interchangeable labels, though, and each serves a different audience and purpose. See our full comparison guide for the specifics.
Ready to See Where Your Controls Stand?
TISAX itself has to be assessed by an ENX-accredited third-party auditor, and LeadingIT does not perform that audit or issue labels. What we do is build the technical backbone underneath it: access controls, patch management, incident response, and tested backups, mapped to the VDA ISA chapters that matter for your assessment level.
If your business is heading toward a TISAX label, our compliance-readiness IT services can get your controls audit-ready before you spend money on a formal assessment. Book a call to talk through where you stand, or contact us with questions.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
