Automotive industry assessment

TISAX

TISAX is the automotive industry’s assessment and exchange mechanism for information security — based on the VDA ISA catalogue and governed by the ENX Association. Without valid TISAX labels it is increasingly difficult to remain a supplier to automotive OEMs.

Start assessmentRead about the standard
86
controls in Guardiso
31
free-test questions
PL · EN
two languages

What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is an information security assessment mechanism created by the German automotive industry association VDA and governed by the ENX Association. Assessments are based on the VDA ISA (Information Security Assessment) requirements catalogue, which builds on ISO/IEC 27001 but extends it with automotive-specific requirements — notably prototype protection and personal data protection.

The core idea of TISAX is result sharing: a company is assessed once and shares the result (as TISAX labels) with all its customers and partners via the ENX platform. A supplier therefore does not need a separate security audit for every OEM — one assessment, many recipients.

Who does it apply to?

TISAX applies to virtually the entire automotive supply chain: parts and component manufacturers, engineering and design firms, software and IT service providers, marketing agencies working with launch material, logistics companies and development centres. Formally TISAX is not a legal requirement — it is a contractual one: automotive OEMs (including Volkswagen, BMW and Mercedes-Benz) require valid TISAX labels from suppliers who handle their confidential information.

In practice the requirement cascades down the chain: Tier 1 suppliers require labels from their own sub-suppliers whenever they touch OEM-protected information. For many companies, including Polish ones, TISAX has become a precondition for winning tenders and keeping automotive contracts.

Assessment levels

TISAX defines three assessment levels, chosen according to the sensitivity of the information handled. A successful assessment results in TISAX labels matching the protection scope the customer requires.

  • AL1 — a self-assessment without auditor verification; it does not produce TISAX labels and is used for supporting purposes.
  • AL2 — a remote assessment: the auditor verifies the plausibility of the self-assessment through documentation and interviews (typical for information with "high" protection needs).
  • AL3 — an on-site assessment including a physical inspection (required for "very high" information, prototype protection and the strictest OEM requirements).
  • Labels include, among others: Information security High / Very High, Prototype protection and Data protection (processing personal data under Art. 28 GDPR).

What does the process look like?

Obtaining TISAX labels follows a fixed process governed by the ENX Association and typically takes from a few months up to a year, depending on the organisation’s maturity.

  • Register the company and assessment scope on the ENX platform and select the required labels.
  • Self-assess against the VDA ISA catalogue — rate the maturity of each requirement and close gaps before the audit.
  • Be assessed by an ENX-accredited audit provider (at AL2 or AL3), with a corrective action plan if findings remain.
  • Publish results on the ENX platform and share labels with chosen partners — TISAX labels are valid for 3 years, after which a re-assessment is required.

How does Guardiso help?

Guardiso guides you through TISAX preparation from the first self-assessment to audit readiness. The platform includes a complete set of controls mirroring the VDA ISA catalogue — including the prototype protection and data protection modules — with descriptions, maturity criteria and mapping to ISO/IEC 27001, so work done for ISO 27001 automatically feeds your TISAX compliance.

You attach evidence to each control (policies, procedures, records, configuration screenshots), and the compliance dashboard continuously shows your coverage and the gaps to close before the assessment. The free TISAX self-assessment in Guardiso shows within minutes how far you are from readiness — before you register on the ENX platform and engage an auditor.

Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
TISAX readiness score
0/31 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards