Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is TISAX? The VDA ISA Standard Explained for Automotive Suppliers

August 11, 2026
hero-what-is-tisax-1.png

TISAX stands for Trusted Information Security Assessment Exchange. It’s an assessment and result-sharing system built for the automotive industry. The ENX Association runs it on VDA’s behalf.

TISAX is not a government regulation. No law requires it. But a growing number of automakers and suppliers now demand a current TISAX label before they’ll sign a contract. For a supplier, that makes TISAX effectively mandatory, even though no regulator enforces it.

This guide explains what TISAX actually requires: the VDA ISA catalogue, the assessment process, and the three Assessment Levels. If your customer just asked for a TISAX label, start here.

Who Created and Runs TISAX

Two organizations run TISAX, and they play different roles.

The VDA (Verband der Automobilindustrie) is the German Association of the Automotive Industry. It publishes the VDA ISA catalogue, the requirements TISAX assessments are scored against. The VDA updates this catalogue periodically.

The ENX Association handles everything day to day. ENX is a nonprofit set up by European vehicle manufacturers and suppliers. It accredits the third-party audit providers who perform TISAX assessments. It maintains the accreditation criteria. It monitors assessment quality across auditors. That way, a label from one provider means the same thing as one from another provider.

ENX doesn’t work alone. A TISAX Committee supports it, made up of representatives from manufacturers, suppliers, and industry associations. This committee helps keep the standard aligned with what the industry actually needs.

Worth repeating: TISAX is not a law. No government agency wrote it. No regulator enforces it. It’s an industry-run standard that works because enough OEMs and Tier 1 suppliers require it in their contracts.

The VDA ISA Catalogue: Nine Chapters Built on ISO 27001

The VDA ISA is the requirements catalogue every TISAX assessment is scored against. ISA stands for Information Security Assessment. It’s built on key parts of ISO/IEC 27001, the international information security standard, but organized specifically for automotive supply chains.

The catalogue splits into nine chapters:

ChapterFocus Area
1IS Policies and Organization
2Organizational Security
3Personnel Security
4Physical and Environmental Security
5Identity and Access Management
6IT Security and Operations
7Detection and Response to Security Incidents
8Business Continuity
9Compliance and Data Protection

Each chapter contains specific audit objectives.

Not every objective applies to every supplier. TISAX groups objectives into three assessment modules: information security, prototype protection, and data protection. Which modules apply depends on your customer’s contract. A supplier who only touches ordinary business data gets scored on the information security module. A supplier building pre-production parts also gets scored on prototype protection.

The catalogue also splits every requirement into two types. A MUST requirement is mandatory. It has to reach Maturity Level 3 or higher for the assessment to pass. A SHOULD requirement is recommended but not mandatory.

A gap on a MUST requirement is serious. It’s called a Major Non-Conformity. You typically get up to nine months to fix it before the assessment can be finalized. A gap on a SHOULD requirement is a Minor Non-Conformity. It gets documented, but it doesn’t block you from passing.

How TISAX Actually Works: Registration, Assessment, Exchange

TISAX runs through three stages on the ENX platform.

TISAX Three-Stage Process
  1. Registration. Create an account, provide company details, and define the assessment objectives your customer requires. This step is self-service. If your registered scope is slightly off, the audit provider can usually still work with it.
  2. Self-assessment and audit. Pick an accredited third-party audit provider, complete the VDA ISA self-assessment, then go through the audit itself. The provider verifies your answers at the Assessment Level your customer requires, then uploads the report and the resulting label.
  3. Exchange. Decide which business partners can see your results, and at what level of detail. Once you grant a partner access, you can’t revoke it. Choose carefully.

That’s the short version. For the full walkthrough, including timelines and fees, see how the TISAX certification process actually works, step by step.

TISAX Assessment Levels and Maturity Levels at a Glance

TISAX doesn’t verify every supplier the same way. It scales the rigor of the check to how sensitive the information is. That’s what Assessment Levels are for.

AL 1 is self-assessment only. You answer the VDA ISA questionnaire, and an auditor checks that you completed it. Nobody verifies whether your answers are accurate. Because of that, AL 1 results carry low trust. TISAX doesn’t accept them for exchange between partners.

AL 2 adds a real check. An accredited auditor reviews your self-assessment, examines your supporting evidence, and interviews your security lead, usually over a web conference. An on-site visit is available if requested. It’s designed to be compatible with upgrading to AL 3 later.

AL 3 is the most rigorous level. It’s a full on-site audit that includes:

  • Document and evidence review
  • Planned interviews with the people who own each process
  • Observation of how those processes actually run day to day
  • Unplanned interviews, to test whether real practice matches what’s written down

A temporary remote version has been allowed, but it still requires an on-site follow-up.

Higher levels automatically satisfy the requirements of lower ones. If your customer requires AL 3, you don’t need to separately pass AL 1 or AL 2.

Which level applies to you depends on your customer’s contract, not your own preference. For the full breakdown, see which TISAX Assessment Level (AL1/AL2/AL3) applies to your business.

Every audited objective also gets scored on a maturity scale, separate from the Assessment Level itself.

LevelNameWhat It Means
0IncompleteNo suitable process exists or is followed
1PerformedAn informal process exists, with some evidence it works, but it’s poorly documented
2ManagedA documented process is followed, with evidence of implementation
3EstablishedA standard process is integrated into the overall management system
4PredictableThe process is measured and controlled
5OptimizingThe process improves continuously based on business goals

This scale matters because passing isn’t about paperwork. To earn a TISAX label, every relevant MUST requirement has to hit Maturity Level 3 or higher. Real evidence has to back it up. A policy document alone, without proof it’s actually followed, won’t pass.

Who Actually Needs TISAX

TISAX isn’t limited to car manufacturers. It reaches almost anyone in the automotive supply chain who touches an OEM’s confidential data, prototypes, or personal information covered by GDPR.

That includes:

Supplier TypeWhy TISAX Applies
Parts and component suppliersHandle confidential specs, drawings, and production data
Engineering and design vendorsAccess unreleased vehicle designs and technical documentation
Prototype and pre-series handlersPhysically store or transport pre-release vehicle parts
IT and software vendorsBuild or host systems that touch automotive client data
Logistics providersMove parts, prototypes, or data between supply chain partners
Any subcontractorCreates, stores, or transmits a partner’s confidential or personal data

Here’s the part that trips people up. There’s no law that names any of these businesses and requires TISAX. The obligation shows up in a different place: the contract.

More OEMs and Tier 1 suppliers now write a current TISAX label into their RFQs and supplier agreements. If you want the business, you need the label. That’s what makes TISAX contractual rather than legal.

This is also why a business’s own subcontractors can get pulled in. If your company needs TISAX to keep a contract, and you use a smaller IT vendor or logistics partner who touches that same data, your customer may expect that partner to meet a comparable bar too.

Not sure whether your organization falls into scope, or which VDA ISA chapters actually apply to your operations? Self-check your organization against the VDA ISA catalogue before you engage an auditor before you spend money on an audit provider.

Not a Law, But No Label Can Mean No Contract

TISAX carries no government fines. There’s no regulator who can penalize you for skipping it. In that narrow sense, it’s nothing like GDPR or HIPAA.

TISAX has no statutory penalties. Its enforcement is commercial: a missing or expired label can get a supplier excluded from bids or dropped at contract renewal.

That commercial pressure is real, and it moves fast. A supplier without a current, in-scope label can be excluded from a bid entirely. An existing supplier can lose a contract at renewal time. Neither of those requires a courtroom.

Inside the assessment itself, there’s a second layer of consequence. An unresolved Major Non-Conformity on a MUST requirement blocks your label from being issued at all. You typically get up to nine months to close that gap before the assessment can be finalized. Miss that window, and you’re back to square one with your customer waiting.

So the honest way to describe TISAX enforcement is: no fines, but real business consequences that can hit faster than most regulatory penalties would.

Why TISAX Has Become Table Stakes

It’s grown well past that.

In December 2025, the number of TISAX-assessed locations with a valid label passed 20,000 worldwide for the first time, according to ENX Association. That’s not 20,000 companies asked about TISAX. That’s 20,000 locations that completed the process and hold a current label.

The geographic spread tells you this isn’t a European-only concern anymore:

RankCountry
1Germany
2China
3USA
4Czechia
5India
6Spain
7Mexico
8Italy
9Poland
10Brazil

The USA ranks third globally. If you supply, engineer for, or move parts for a global automaker, there’s a good chance your competitors already hold a label, or are working toward one.

That’s the practical reason TISAX has become table stakes rather than a nice-to-have. When enough of a supply base has a label, a customer stops asking “do you have TISAX” as a courtesy question and starts treating it as a bid requirement.

What Getting Audit-Ready Actually Takes

Here’s where most small and mid-size suppliers get stuck. The VDA ISA catalogue reads like a compliance document. What it’s actually asking for, chapter by chapter, is IT infrastructure that has to already be working before an auditor shows up.

Four chapters carry most of the technical weight:

Spec block naming the core VDA ISA chapters: Identity and Access Management, IT Security and Operations, Detection and Response, and Business Continuity.
  • Chapter 5, Identity and Access Management. Unique user IDs, multifactor authentication, least-privilege access, and encryption for sensitive data.
  • Chapter 6, IT Security and Operations. Patch management, change management, active monitoring, and backups that are actually tested, not just scheduled.
  • Chapter 7, Detection and Response. A real incident logging process and a documented response procedure, not just a plan on paper.
  • Chapter 8, Business Continuity. Disaster recovery planning with a defined recovery time objective and recovery point objective, tested under real conditions.

Remember the maturity model from earlier: hitting Level 3 or higher means a documented, standard process that’s actually integrated into how your business runs, not a policy binder nobody follows. An auditor at AL 2 or AL 3 will ask to see evidence, not just hear a description.

This is the gap between “we have a firewall” and “we can prove, with logs and documentation, that access is controlled, patches are current, incidents get logged, and we could recover from an outage.” Most small and mid-size suppliers have pieces of this in place informally. Getting audit-ready means turning those informal habits into a documented, consistent process across every MUST requirement your customer’s scope requires.

That’s the kind of foundational IT work that either gets built ahead of an audit, or gets discovered as gaps during one. LeadingIT’s compliance-readiness IT services (done-for-you path) exist to build and document those controls before an auditor is in the room, and to help maintain them across the three-year label cycle. LeadingIT doesn’t perform TISAX audits or issue labels; that work belongs to ENX-accredited third-party audit providers. What LeadingIT does is make sure the technical foundation those auditors are checking is actually there.

See Where You Stand

Not sure where your gaps are before you talk to an audit provider? Answer a few plain-English questions mapped to the VDA ISA chapters that trip up first-time suppliers, and see your readiness level and specific gaps to close.

Take the free 2-minute TISAX Readiness Check

Frequently Asked Questions

No, but they’re related. The VDA ISA catalogue that TISAX assessments are scored against is built on key parts of ISO/IEC 27001. TISAX adds automotive-specific requirements, like prototype protection, and a result-exchange system ISO 27001 doesn’t have. A company with ISO 27001 certification still has to complete a separate TISAX assessment.

ENX Association doesn’t publish a standard timeline, and says it can’t forecast one reliably. Timing depends on your Assessment Level, how ready your controls are going in, and your audit provider’s availability. AL 1 is fastest since it’s self-assessment only. AL 3 takes longest, since it includes a full on-site audit with planned and unplanned interviews.

Three years. After that, you have to repeat the full three-stage process, registration, assessment, and exchange, to renew your label. This three-year validity is part of what makes TISAX efficient for suppliers who work with multiple OEMs: one assessment can be shared with every partner who requests it.

Only third-party audit providers that ENX Association has separately accredited can conduct a TISAX assessment. Becoming an accredited provider is a distinct process from being a participant who gets assessed. Most IT service providers, including LeadingIT, are not accredited audit providers and don’t issue TISAX labels.

If a customer requires it in your contract, size doesn’t exempt you. TISAX applies to any organization an OEM or Tier 1 supplier requires to demonstrate information security, regardless of headcount. A small engineering or IT vendor handling confidential automotive data can be held to the same requirement as a large manufacturer.

A gap on a MUST requirement is called a Major Non-Conformity, and it blocks your label from being issued. You typically get up to nine months to fix it before the assessment can be finalized. A gap on a SHOULD requirement is a Minor Non-Conformity, which gets documented but doesn’t block passing.

No. The Assessment Level you need, AL 1, AL 2, or AL 3, is determined by your customer based on how sensitive the information or prototype material you’ll handle is. You can’t self-select a lower level to save time or cost if your customer’s contract requires a higher one.

Ready to Close Your TISAX Gaps?

TISAX assessments succeed or fail on the IT controls behind them, not the paperwork. If your customer has asked for a label and you’re not sure your infrastructure would hold up under an AL 2 or AL 3 audit, that’s worth finding out before an auditor does.

LeadingIT’s compliance-readiness IT services help Chicagoland automotive suppliers build and document the controls TISAX auditors check.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.