What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment mechanism created by the German automotive industry association VDA and governed by the ENX Association. Assessments are based on the VDA ISA (Information Security Assessment) requirements catalogue, which builds on ISO/IEC 27001 but extends it with automotive-specific requirements — notably prototype protection and personal data protection.
The core idea of TISAX is result sharing: a company is assessed once and shares the result (as TISAX labels) with all its customers and partners via the ENX platform. A supplier therefore does not need a separate security audit for every OEM — one assessment, many recipients.
Who does it apply to?
TISAX applies to virtually the entire automotive supply chain: parts and component manufacturers, engineering and design firms, software and IT service providers, marketing agencies working with launch material, logistics companies and development centres. Formally TISAX is not a legal requirement — it is a contractual one: automotive OEMs (including Volkswagen, BMW and Mercedes-Benz) require valid TISAX labels from suppliers who handle their confidential information.
In practice the requirement cascades down the chain: Tier 1 suppliers require labels from their own sub-suppliers whenever they touch OEM-protected information. For many companies, including Polish ones, TISAX has become a precondition for winning tenders and keeping automotive contracts.
Assessment levels
TISAX defines three assessment levels, chosen according to the sensitivity of the information handled. A successful assessment results in TISAX labels matching the protection scope the customer requires.
- AL1 — a self-assessment without auditor verification; it does not produce TISAX labels and is used for supporting purposes.
- AL2 — a remote assessment: the auditor verifies the plausibility of the self-assessment through documentation and interviews (typical for information with "high" protection needs).
- AL3 — an on-site assessment including a physical inspection (required for "very high" information, prototype protection and the strictest OEM requirements).
- Labels include, among others: Information security High / Very High, Prototype protection and Data protection (processing personal data under Art. 28 GDPR).
What does the process look like?
Obtaining TISAX labels follows a fixed process governed by the ENX Association and typically takes from a few months up to a year, depending on the organisation’s maturity.
- Register the company and assessment scope on the ENX platform and select the required labels.
- Self-assess against the VDA ISA catalogue — rate the maturity of each requirement and close gaps before the audit.
- Be assessed by an ENX-accredited audit provider (at AL2 or AL3), with a corrective action plan if findings remain.
- Publish results on the ENX platform and share labels with chosen partners — TISAX labels are valid for 3 years, after which a re-assessment is required.
How does Guardiso help?
Guardiso guides you through TISAX preparation from the first self-assessment to audit readiness. The platform includes a complete set of controls mirroring the VDA ISA catalogue — including the prototype protection and data protection modules — with descriptions, maturity criteria and mapping to ISO/IEC 27001, so work done for ISO 27001 automatically feeds your TISAX compliance.
You attach evidence to each control (policies, procedures, records, configuration screenshots), and the compliance dashboard continuously shows your coverage and the gaps to close before the assessment. The free TISAX self-assessment in Guardiso shows within minutes how far you are from readiness — before you register on the ENX platform and engage an auditor.
