What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is the information-security assessment and exchange mechanism used by the German automotive industry. It is governed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA), and it is built on the VDA ISA (Information Security Assessment) catalogue.

Strictly speaking, TISAX is not a certificate in the ISO sense. You undergo an assessment by an ENX-approved audit provider, and the result is a TISAX label published to the ENX exchange portal, which you then share with the customers who require it. The label is valid for three years.

Key focus: Information security, prototype protection, and data protection across the automotive supply chain.

Why is TISAX important?

Automotive OEMs share highly sensitive information with their suppliers — designs, prototypes, source code, and personal data. Rather than every manufacturer auditing every supplier separately, TISAX creates one assessment that many customers accept. You are assessed once, and you share the result with each OEM through the ENX portal.

Key Insight

For most automotive suppliers TISAX is not optional. Volkswagen, BMW, Mercedes-Benz, Audi, Porsche, Bosch and Continental routinely require a valid TISAX label before releasing sensitive data or awarding contracts. Without it, you can be excluded from the tender entirely.

Who needs TISAX?

TISAX applies to any organisation that handles sensitive information on behalf of an automotive manufacturer or Tier 1 supplier, including:

Automotive suppliers (Tier 1, Tier 2 and below) handling designs or specifications; engineering and design service providers; software and IT/SaaS vendors serving automotive clients; prototype builders, testing and tooling firms; and marketing, logistics and data-processing partners that touch automotive data.

If an OEM has asked you to "get TISAX" or to register on the ENX portal, this page is your starting point. Talk to an Avantcert expert to confirm the scope and assessment level you actually need.

TISAX assessment levels (AL 1, AL 2, AL 3)

Your customer specifies the assessment level based on the protection needs of the information you handle:

Assessment Level 1 (AL 1) — a self-assessment only, with no independent verification. Rarely sufficient on its own for OEM requirements.

Assessment Level 2 (AL 2) — the most common level. The audit provider reviews your self-assessment and evidence, typically with a remote plausibility check or interview. Applies to information with high protection needs.

Assessment Level 3 (AL 3) — the most rigorous level, with a comprehensive on-site audit and in-depth verification. Applies to very high protection needs, such as prototype protection.

TISAX labels and scope

TISAX is not one single label. You are assessed against the scope your customer requires, and you receive labels accordingly. The main label families are:

Information Security — the core label, covering your information-security management system. Prototype Protection — additional physical and organisational controls for handling prototype vehicles, parts and test data, usually assessed at AL 3. Data Protection — controls aligned to GDPR requirements where you process personal data on behalf of the customer.

Choosing the wrong scope is one of the most expensive mistakes in a TISAX project: too narrow and your customer rejects the label; too broad and you pay for controls you did not need. Avantcert scopes this correctly before any assessment is booked.

VDA ISA requirements

TISAX assessments are conducted against the VDA ISA catalogue, a control set that is closely aligned with ISO 27001. It is organised into modules covering information security, prototype protection and data protection, and each control is scored on a maturity scale (from 0, incomplete, up to 5, optimising). Most customers expect a target maturity of 3 across the applicable controls.

If you already hold ISO 27001 certification, you have a substantial head start — much of the evidence, policy set and risk-management framework carries directly across, which shortens the TISAX project and reduces cost.

TISAX implementation process

Avantcert follows a proven four-stage methodology for TISAX:

1. Scoping and gap analysis. We confirm the assessment level, locations and labels your customer requires, then measure your current controls against the VDA ISA catalogue and produce a maturity scorecard.

2. Implementation. We close the gaps — policies, risk management, access control, supplier management, physical security, incident response and (where in scope) prototype-protection and data-protection controls.

3. Internal audit and self-assessment. We complete the VDA ISA self-assessment with you, verify the maturity scores are evidenced, and run a mock assessment so there are no surprises.

4. Assessment support. We prepare your team, support you through the ENX-approved audit provider's assessment, and manage any corrective actions through to the issued label.

The TISAX assessment and the ENX portal

You register your company and your scope on the ENX portal, then engage an ENX-approved audit provider — Avantcert prepares you for the assessment; the assessment itself must be performed by an approved provider, not by your consultant. Once you pass, your result is published to the portal as a TISAX label.

Unlike an ISO certificate, a TISAX label is not a public document you print and display. It lives in the exchange, and you actively share it with each customer who needs to see it. The label is valid for three years, after which you reassess.

Benefits of TISAX

Market access. A valid label removes the single biggest blocker to winning and keeping German automotive contracts.

Assess once, share many times. One assessment satisfies multiple OEMs and Tier 1 customers, instead of a separate audit for each.

Genuinely stronger security. The VDA ISA controls materially reduce the risk of breach, IP theft and prototype leaks.

A foundation for other standards. The work overlaps heavily with ISO 27001, so pursuing both together is far cheaper than doing them separately.

TISAX cost and timeline

With Avantcert, TISAX costs $8,000 to $35,000 and takes up to 4 months. A small supplier at AL 2 with a single site sits at the lower end; a large enterprise at AL 3 with prototype protection and multiple locations sits at the upper end. Prices are already 30-50% below typical market rates.

The biggest cost drivers are your assessment level (AL 3 requires an on-site audit), the number of locations in scope, how many labels you need, and whether you already hold ISO 27001. Note that the ENX-approved audit provider's fee is billed separately from preparation.

Get an exact figure for your scope with our free certification cost calculator, or request a scoped quote.

TISAX FAQs

What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is the German automotive industry's information-security assessment and exchange mechanism, governed by the ENX Association on behalf of the VDA and based on the VDA ISA catalogue.

Who needs TISAX?

Any supplier, engineering firm, or IT/software vendor that handles sensitive information for automotive manufacturers such as Volkswagen, BMW, Mercedes-Benz, Audi or Porsche, or for their Tier 1 suppliers.

Is TISAX a certification?

Not in the ISO sense. You are assessed by an ENX-approved audit provider and receive a TISAX label, which you share with your customers through the ENX portal rather than displaying publicly.

What are the TISAX assessment levels?

AL 1 is a self-assessment; AL 2 adds an evidence review and remote plausibility check and is the most common; AL 3 requires a comprehensive on-site audit and applies to very high protection needs such as prototype protection.

What is the difference between TISAX and ISO 27001?

ISO 27001 is a globally certifiable information-security standard; TISAX is automotive-specific and based on the VDA ISA catalogue, which is closely aligned with ISO 27001. Holding ISO 27001 gives you a significant head start on TISAX.

How long is a TISAX label valid?

Three years, after which you must be reassessed to keep sharing a valid label with your customers.

How much does TISAX cost and how long does it take?

With Avantcert, TISAX costs $8,000 to $35,000 and takes up to 4 months, depending on assessment level, locations and labels in scope. Prices are already 30-50% below market — request a free quote.

About Avantcert

Avantcert is an accredited ISO and compliance certification consultancy that helps organizations achieve TISAX through VDA ISA gap analysis, implementation, and assessment support. Avantcert has supported 3,000+ organizations across 40+ markets, following a proven four-stage methodology — Gap Analysis, Implementation, Internal Audit, and Assessment. To begin your TISAX project, request a free quote or talk to an Avantcert expert.

Related certifications

Avantcert also helps organizations achieve these related standards — often alongside TISAX as part of one programme: ISO 27001, IATF 16949, ISO 9001, GDPR, VAPT, SOC 2. Not sure which you need? Use the free estimator or talk to an expert.

Official reference: ENX Association — TISAX.

Ready to start your TISAX journey?

Get expert guidance and resources to achieve your TISAX label