Automotive | Information Security
TISAX: Information Security in the Automotive Industry
TISAX is the automotive industry's standard for information security in the supply chain. OEMs such as BMW, Mercedes-Benz and Volkswagen require a valid TISAX label from their suppliers - without it, collaboration on protected projects is not possible. The standard is operated internationally by the ENX Association on behalf of the VDA.
Last updated: March 2026
- Assessment Levels
- 3
- Registration Body
- ENX
- Questionnaire
- VDA ISA
- Validity
- 3 Years
Fundamentals
What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standard for information security in the supply chain. Developed by the ENX Association in close collaboration with the VDA, it is today a mandatory prerequisite for suppliers processing sensitive information from OEMs.
What makes TISAX unique: the assessment result is determined once by an accredited audit service provider and then shared selectively with multiple customers through the ENX platform. Suppliers do not need a separate assessment for each OEM - a significant efficiency gain compared to individual supplier audits.
Content-wise, TISAX is based on the VDA ISA questionnaire and covers all essential information security domains - supplemented by automotive-specific topics such as prototype protection and data privacy in the automotive context.
Audit Depth
The Three TISAX Assessment Levels
The required assessment level is determined by the protection needs of the information processed and the requirements of the customer. The higher the protection requirement, the more intensive the audit.
Self-Assessment
The supplier self-assesses against the VDA ISA. An accredited audit service provider checks the plausibility of the responses remotely - without in-depth on-site verification.
- Self-assessment by the supplier
- Remote plausibility check
- No personal interview
- Lowest effort and cost
Remote Assessment
An accredited audit service provider conducts a structured remote interview and evaluates the supplier's evidence. This level is the standard for the vast majority of TISAX assessments.
- Structured remote interview
- Assessment by auditor
- Evidence documentation required
- Standard for most suppliers
On-Site Assessment
Complete assessment by an accredited audit service provider at the supplier's premises. Physical inspection, system checks and in-depth interviews are part of the assessment.
- Physical on-site audit
- System checks at the premises
- In-depth interviews with responsible personnel
- Highest audit intensity and cost
Process
TISAX Process: 5 Steps to the Label
From the decision to pursue TISAX to the issued label, there are five clearly structured steps. The total duration is typically 3-9 months - depending on the starting situation and the required assessment level.
Scope Definition and ENX Registration
The company determines which locations, systems and processes fall within the TISAX scope. Registration with the ENX Association follows, with selection of the assessment objective (information security, prototype protection and/or data privacy) and assessment level. ENX issues an access code for the platform.
Self-Assessment against VDA ISA
The company answers all relevant questions in the VDA ISA questionnaire on the ENX platform. Each question requires a maturity rating (0-3) and indication of evidence. This phase uncovers gaps and forms the basis for the subsequent gap analysis.
Gap Analysis and Remediation
Unfulfilled or only partially fulfilled requirements identified in the self-assessment are documented. Concrete measures are defined, prioritized and implemented for each gap. This step is typically the most resource-intensive - especially when no structured ISMS is already in place.
Assessment by Accredited Audit Service Provider
An ENX Association-accredited audit service provider conducts the assessment - depending on the level as a plausibility check (AL 1), remote interview (AL 2) or on-site assessment (AL 3). The auditor evaluates all responses and evidence against the VDA ISA and produces an audit report.
TISAX Label and Exchange via ENX Portal
After a successful assessment, the TISAX label is stored in the ENX platform. The company can now selectively share the label with customers - without disclosing the full audit report. The label is valid for three years; the re-assessment should be planned 12 months before expiry.
Content
The VDA ISA Questionnaire: What Gets Assessed
The VDA ISA (currently Version 6.0, valid since 2024) is the heart of every TISAX assessment. It is divided into three modules, of which the first is mandatory.
Information Security
Mandatory module for all assessments
- Security policies and organization
- Physical and environmental security
- IT systems and networks
- Identity and access management
- Cryptography
- Incident and vulnerability management
- Business continuity
- Compliance and auditing
- Supplier and vendor management
Prototype Protection
Optional module for prototype handling
- Protection of unreleased vehicle models and parts
- Photography and video restrictions
- Physical security of prototype areas
- Labeling and handling of prototype materials
- Transport protection for test vehicles
- Third-party requirements in prototype involvement
- Incident management for prototype leaks
Data Privacy
Optional module - GDPR context
- Data privacy organization and responsibilities
- Legal bases for data processing
- Data subject rights and requests
- Technical data privacy measures (TOMs)
- Data processing agreements and third-country transfers
- Data Protection Impact Assessments (DPIA)
- Data breach management and reporting obligations
Synergies
TISAX and ISO 27001: Maximizing Synergies
TISAX and ISO 27001 overlap by approximately 80% in their substantive requirements. Both standards require a functioning Information Security Management System (ISMS), risk-based approach, access control, incident management, business continuity and regular review of security measures.
The TISAX-specific additions primarily concern the automotive context: prototype protection, requirements for production facilities with test vehicles and industry-specific supply chain management requirements. This additional 20% effort is very manageable for ISO 27001-certified companies.
We recommend an integrated approach for automotive suppliers: ISO 27001 as the strategic foundation, TISAX as the automotive-specific extension. This achieves both goals with maximum efficiency. Learn more about our consulting services under Security Consulting.
TISAX in Numbers
Tip: Companies with an existing ISO 27001 ISMS typically reduce their TISAX preparation effort by 60-70%. An integrated project saves time and cost - ask us about our ISO 27001 plus TISAX package.
„Implementing ISO 27001 and TISAX together is not double the work - it is strategic resource management. 80% of requirements overlap; those who leverage that achieve both goals faster and more cost-effectively than with two separate projects.“
Oskar Braun
ISO 27001 Lead Auditor (IRCA-certified) · AWARE7 GmbH
Why AWARE7 for Your TISAX Preparation
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees - tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies analyse millions of websites and tens of thousands of phishing emails - published at ACM and Springer conferences. Three of our executives are professors at German universities at the same time.
Digital sovereignty - no compromises
100 %All data is stored and processed exclusively in Germany - without US cloud providers. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations. VS-NfD compliant on request.
Fixed price within 24h - predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security - without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house - and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA - we know the requirements and deliver evidence that auditors accept.
Frequently Asked Questions about TISAX
Answers to the most common questions about TISAX assessments, VDA ISA and preparation in the automotive supply chain.
What is TISAX?
Who needs a TISAX label?
What are the 3 TISAX Assessment Levels?
How does a TISAX assessment work?
What does a TISAX assessment cost?
What is the VDA ISA questionnaire?
How are TISAX and ISO 27001 related?
How does AWARE7 support companies with TISAX?
Aus dem Blog
Weiterführende Artikel
Clubhouse - Was bedeutet die Hype-App für Informationssicherheit
Wer in diesen Tagen die einschlägigen IT-Portale besucht der kommt kaum drum herum: Clubhouse ist der hellste Stern am Social Network-Himmel.
Der Informationssicherheitsbeauftragte - Zuständigkeiten und Aufgaben!
Der Informationssicherheitsbeauftragte ist der Ansprechpartner für Informationssicherheit im Unternehmen. Diese Aufgaben hat er!
10 häufige Fehler bei Informationssicherheits-Schulungen vermeiden
Vermeiden Sie die häufigsten Fehler bei Mitarbeiterschulungen zur Informationssicherheit und stärken Sie Ihre Sicherheitskultur nachhaltig
Pass Your TISAX Assessment Successfully
AWARE7 guides you from gap analysis to the issued label - with an integrated approach that efficiently combines ISO 27001 and TISAX. Fixed-price proposal after a free initial assessment.
Kostenlos · 30 Minuten · Unverbindlich