- What they do
- Assessor
- Which standards
- On the public register for TISAX.
- Standards
- Pricing
- Not published
Framework Information Security & Privacy
TISAX
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's shared assessment and exchange mechanism for supplier information security, run by the ENX Association on behalf of the German Association of the Automotive Industry (VDA).
Suppliers are assessed against the VDA Information Security Assessment (ISA) catalog; ISA version 6 has applied to assessments commissioned since April 1, 2024. Results are not published as certificates but as labels on the ENX portal that the supplier shares with the OEMs and partners that require them.
Labels currently cover confidentiality (Confidential, Strictly Confidential), availability (High Availability, Very High Availability), prototype protection and data protection objectives.
The assessment level depends on the protection need: AL1 is a self-assessment, AL2 is a remote plausibility check of the self-assessment by an audit provider, and AL3 is an on-site assessment with interviews and inspection.
To pass, the supplier must reach maturity level 3 across the requirements, meaning the ISMS is documented and demonstrably operated: an information security policy set, risk management, asset classification, access control, supplier security, incident management, business continuity, and for prototype and data protection objectives, the corresponding specialized policies.
Labels are valid for three years.
Who has to comply
Contractual. Suppliers, service providers and development partners whose automotive customers (mainly German OEMs and tier-one suppliers, increasingly others worldwide) require TISAX labels before sharing information with a high protection need. The customer specifies the assessment objectives and level.
What the assessor asks to see
ENX participant and scope registration; completed ISA self-assessment with maturity ratings; information security policy and ISMS documentation; risk assessment and treatment; asset inventory and classification; access control and identity management records; supplier and partner security agreements; incident management records; business continuity and backup evidence; for prototype protection, physical security and handling procedures; for data protection, GDPR processing documentation; on-site inspection at AL3.
Where the requirement sits: VDA ISA controls (information security, prototype protection, data protection) at maturity levels 0-5
Assessment levels and labels
AL1: self-assessment only, no label of practical value to most customers. AL2: audit provider reviews the self-assessment and evidence remotely. AL3: full on-site assessment.
With ISA 6 the former Info High and Info Very High labels were split into confidentiality labels (Confidential, Strictly Confidential) and availability labels (High Availability, Very High Availability); holders of the old labels were assigned the new confidentiality labels automatically. Prototype protection and data protection objectives carry their own labels.
What AllyMatter does here
Policy layer of the ISA catalogue.
AllyMatter publishes this site.
Assessors
Who assesses TISAX
An ENX-approved TISAX audit provider (approval decided by the TISAX Committee) using auditors qualified for the ISA. Only approved providers can perform AL2 and AL3 assessments that produce labels.
Accredited by ENX Association approves audit providers and monitors their quality; there is no national accreditation body in the chain, although many providers are also accredited certification bodies for ISO 27001.
Public register of assessors: https://portal.enx.com/en-us/tisax/xap/
- What they do
- Assessor
- Which standards
- On the public register for TISAX.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for TISAX.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for TISAX.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for TISAX.
- Standards
- Pricing
- Not published
Consultants
Who helps with TISAX
Yes. Information security consultancies, especially in Germany and Central Europe, offer ISA gap assessments, ISMS documentation, self-assessment preparation and audit accompaniment. Engagements typically run three to nine months before the audit.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a TISAX consultant listing yet. Claim yours →
Software
Tools for TISAX
Tools that name this framework in their own material.
Related reading
- Transition to TISAX VDA ISA version 6An assessment body explains the ISA 6 label rename, the new availability label and how existing labels carry over.DNV
- What is TISAX? The complete guide to automotive information security assessmentsWalks through assessment levels, the ENX exchange model and what an auditor tests at each level.NRI Secure
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for TISAX
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of TISAX in AllyMatter
Approve the policies TISAX asks for, keep every version, and record a named acknowledgment from each person who has to read them.