Certification on TISAX®:
requirements, process, and automotive relevance

TISAX® sets the standard for information security in the automotive industry. Understand what it requires and how to meet it.

  • What TISAX® is and how it differs from traditional certifications
  • Key requirements, assessment levels, and the certification process
  • How to prepare efficiently and meet OEM expectations
framework_TISAX_pillar

What is TISAX®?

TISAX® establishes a standardized approach to information security assessments across the automotive industry. It allows companies to prove their security level once and share the results with trusted partners.

Unlike traditional certifications, TISAX® focuses on mutual recognition and controlled result sharing instead of issuing a universal certificate.

Definition of TISAX®

TISAX® stands for Trusted Information Security Assessment Exchange. It is a mechanism that enables organizations to undergo a standardized information security assessment and securely share the results within the automotive network.

The outcome is not a certificate in the classic sense. Instead, participants receive assessment results that can be accessed by authorized partners via the TISAX® platform. This reduces redundant audits and creates a consistent security baseline.

Who defines the requirements for the certification on TISAX®?

TISAX® is based on a combination of governance and technical standards that define how assessments are conducted and what is evaluated.

ENX Association

The ENX Association operates the TISAX® platform and governs the overall framework. It ensures that all participants follow consistent rules and that assessment results can be exchanged in a secure and trusted environment.

VDA ISA catalog

The VDA ISA catalog defines the actual security requirements. It is developed by the German Association of the Automotive Industry and provides a structured set of controls that organizations must implement and verify.

Why TISAX®? The Purpose of Certification

TISAX® creates a shared understanding of security expectations across the automotive supply chain. It replaces fragmented questionnaires and reduces repeated audits by establishing a recognized assessment standard.

Why is TISAX® critical for the automotive industry?

TISAX® is closely aligned with how modern automotive ecosystems operate. Companies exchange large volumes of sensitive information across organizational and geographic boundaries.

Role of TISAX® in the automotive supply chain

The automotive supply chain connects OEMs, tier suppliers and specialized service providers. Each participant handles data that may impact multiple partners.

TISAX® acts as a common security language across this network. Instead of evaluating each partner individually, organizations rely on a shared framework that ensures comparable security levels at every stage.

Why do automotive companies require TISAX®?

Automotive companies manage highly sensitive data throughout the product lifecycle. This includes:

  • Prototype information that must remain confidential
  • Intellectual property that defines competitive advantage
  • Collaboration data shared across global teams

TISAX® provides a structured way to protect this information by ensuring that all participants apply consistent security measures.

Which companies need certification on TISAX®?

TISAX® is relevant for any organization that interacts with automotive partners and processes sensitive information.

This includes:

  • Suppliers providing components or systems
  • Service providers handling data or processes
  • Technology partners delivering software or infrastructure

Even smaller companies may be required to undergo an assessment if they are part of a critical supply chain.

What are the requirements for certification on TISAX®?

TISAX® is based on a comprehensive catalogue of security controls. These requirements define how organizations manage information security, data protection, and specific automotive risks.

Overview of requirements for the assessment on TISAX® (VDA ISA)

The VDA ISA (Information Security Assessment) catalog defines the requirements behind every assessment on TISAX®. It sets out what your organization must implement and how auditors evaluate your security level.

The catalog is structured into domains and control objectives. Each domain focuses on a specific area of information security and combines:

  • Organizational measures such as roles, policies, and governance
  • Technical controls such as access restrictions, system security, and monitoring

Auditors look at how these controls are applied in practice. You need to demonstrate that responsibilities and processes are clearly defined, controls are implemented, and documentation is complete and auditable.

The requirements are grouped into domains such as:

  • Information security organization and governance
  • Human resources security and awareness
  • Identity and access management
  • IT operations security and system protection
  • Supplier and third-party management
  • Incident management and business continuity

Each domain defines clear objectives but allows flexibility in implementation. This ensures that controls fit your company's setup while meeting automotive expectations.

Key security areas covered

TISAX® assessments focus on three core protection areas. These reflect the main risks in the automotive industry and extend beyond standard security frameworks.

Information security

This area evaluates your overall security management approach. It focuses on how you identify, manage, and monitor risks.

Typical requirements include:

The objective is to ensure consistent and controlled security across your organization.

Data protection

Data protection covers how you handle personal data in daily operations. It aligns closely with regulatory expectations.

Auditors assess whether you:

  • Process personal data based on clear rules
  • Apply principles such as data minimization
  • Protect data during storage and transfer
  • Manage data subject requests

The focus lies on secure and transparent data handling.

Prototype protection

Prototype protection is specific to the automotive sector. It addresses risks related to sensitive development assets.

Typical requirements include:

  • Securing facilities and test environments
  • Restricting access to prototypes
  • Preventing unauthorized recordings or leaks
  • Protecting related data and documentation

This ensures that confidential development work remains protected throughout its lifecycle.

How strict are the requirements for the assessment on TISAX®?

The level of strictness depends on the selected assessment level and the expectations of your customers.

OEMs often define minimum requirements that suppliers must fulfill. As a result, companies need to align their security posture with both the VDA ISA catalog and specific contractual expectations.

08_icta_TISAX_right_EN

Get TISAX® certified faster with expert guidance (and with 75% less effort)...


Simplify your TISAX® certification, reduce manual work by up to 75%, and pass your audit on the first try.

What assessment level on TISAX® exist?

TISAX® defines different assessment levels to reflect varying risk profiles. The higher the level, the more rigorous the assessment. Depending on the nature and intensity of the collaboration between the OEM and the supplier, different audit objectives can be defined. Whether a company meets these objectives is assessed based on three TISAX® levels. The general rule is: the greater the need for protection, the higher the level.

Assessment level on TISAX® explained (Level 1, 2, 3)

The three levels differ in terms of audit depth and verification method.

Level

Audit Type

Depth

Typical Use Case

Level 1

Self-assessment

Internal validation

Low-risk scenarios

Level 2

External plausibility check

Limited verification

Medium sensitivity

Level 3

Full external audit

Comprehensive assessment

Highly sensitive data

TISAX® Level 1 defines a “normal” protection level.
This level only requires a self-assessment by the company based on the VDA ISA questionnaire. As a result, there is no independent validation of the assessment outcome, which significantly limits its reliability and practical relevance.

TISAX® Level 2 represents a “high” protection need.
As with Level 1, the company conducts a self-assessment. The key difference is that an external auditor reviews and verifies the results. This verification is typically carried out remotely and focuses on plausibility rather than a full on-site audit.

TISAX® Level 3 corresponds to a “very high” protection need and is the most commonly required assessment level.
The initial evaluation is again based on a self-assessment. However, in this case, an accredited auditor performs a comprehensive verification that goes beyond remote review. This includes on-site inspections and live interviews across all relevant company locations to confirm that controls are consistently implemented in practice.

How to determine the right assessment level

The appropriate assessment level depends primarily on the level of protection required for the information you handle. In practice, this is driven by two factors:

  • Customer requirements defined by OEMs or partners
  • Sensitivity of the information you process

OEMs often specify the minimum assessment level as part of contractual requirements. At the same time, you need to evaluate your own risk exposure based on the type of data and processes in scope.

For example, companies working with prototype data, development information, or other highly confidential assets are typically expected to meet Level 3 requirements. Lower sensitivity scenarios may allow for Level 2, but this depends on the expectations of your customers and the role you play in the supply chain.

How does the certification process on TISAX® work?

Obtaining an assessment on TISAX® follows a structured process. Each step builds on the previous one and requires careful preparation.

Step-by-step certification process

To obtain certification on TISAX®, auditors assess whether your organization meets the information security and prototype protection requirements defined by the ENX Association. The assessment is based on the VDA ISA questionnaire, which sets out the relevant controls and evaluation criteria.

The process includes the following stages:

  • Define the scope of your assessment
  • Build or adjust your information security management system
  • Complete a self-assessment based on the VDA ISA catalog
  • Engage an approved audit provider for external assessment
  • Publish the results on the TISAX® platform

Each step requires documentation and coordination across multiple stakeholders.

What is assessed during an audit for TISAX® ?

Auditors evaluate different aspects of your organization:

  • Security controls and technical safeguards
  • Internal processes and governance structures
  • Documentation supporting your implementation

The goal is to verify that your controls are implemented and effectively maintained.

Role of the PDCA cycle in TISAX®

The PDCA model supports the continuous operation and improvement of your ISMS and helps ensure a successful assessment on TISAX®.

  • Plan: Define your objectives and target label, assess your current state, and identify gaps. Based on this, plan the measures required to meet the requirements for TISAX®
  • Do: Implement the defined measures, adjust processes, and train employees to ensure consistent execution
  • Check: Review results, measure whether objectives are met, and identify areas for improvement based on audits and monitoring
  • Act: Stabilize effective measures, address weaknesses, and refine your approach before starting the next improvement cycle

This structured cycle ensures that your ISMS remains effective over time and continues to meet requirements for an assessment on TISAX®.

How to prepare for an audit on TISAX®?

Preparation determines how smoothly your assessment process runs. A structured approach helps avoid delays and unnecessary effort.

What resources do I need for a certification on TISAX®?

Certification on TISAX® requires time, expertise, and financial resources. Successful preparation and implementation depend on a dedicated team and a clear understanding of the requirements for the assessment on TISAX®.

  • Time: Depending on company size and complexity, the process can take anywhere from three months to up to a year. Project leads need a team with sufficient capacity to implement measures and meet all requirements
  • Budget: Both the implementation of information security measures and the TISAX® assessment itself involve costs. These vary depending on scope, technical complexity, and the chosen audit provider
  • Know-how: Expertise in information security is required to interpret and implement the VDA ISA requirements correctly. Companies can rely on internal specialists or bring in external experts to close knowledge gaps
  • Technology and infrastructure: Networks, software, and hardware must be reviewed and, if necessary, updated to meet TISAX® requirements and support secure operations

Typical challenges during preparation

Many organizations face similar issues, when it comes to the implementation of TISAX®:

  • Lack of a structured framework for security processes
  • Missing or inconsistent documentation
  • Limited internal expertise in requirements for the assessment on TISAX®

These challenges can slow down the assessment if they are not addressed early.

Practical tips for successful audit preparation

A successful preparation approach includes:

Early planning reduces rework and helps align stakeholders.

What labels for a certification on TISAX® and results mean?

TISAX® does not issue certificates, it provides labels that reflect assessment outcomes.

TISAX labels explained

Labels represent the result of an assessment and indicate:

  • The assessment level achieved
  • The scope of the evaluation
  • The domains covered

They provide a clear and comparable summary of your security posture.

Until March 2024, eight TISAX® labels were defined: two for information security, four for prototype protection, and two for data protection. With the transition to VDA ISA version 6 on April 1, 2024, the labels in the area of information security were expanded.

Instead of distinguishing only between “high” and “very high” protection needs, TISAX® now further differentiates based on confidentiality and availability. As a result, there are now four labels within information security alone.

Today, a total of ten labels exist, covering the following areas:

  • Information security: Handling information with high and very high protection needs, differentiated by confidentiality and availability
  • Prototype protection: Protecting parts and components, prototype vehicles, test vehicles, as well as prototypes at events and photo shoots
  • Data protection: Requirements under Article 28 GDPR (data processing agreements) and the handling of special categories of personal data under Article 9 GDPR

Organizations can obtain multiple labels at the same time if they meet different requirements. Depending on their business activities and customer expectations, suppliers often cover several labels and in some cases all of them.

How results are shared in the TISAX® platform

Assessment results are stored within the ENX platform. Companies can grant access to specific partners. This controlled sharing mechanism ensures that sensitive audit results remain protected while still enabling trust within the network.

What does certification on TISAX® cost?

Costs vary depending on the size and complexity of your organization.

Cost factors

A key cost driver is the targeted protection level, combined with the maturity of your existing systems. The following points provide an overview of the main cost components:

  • Audit fees paid to the assessment provider
  • Implementation costs for processes and security controls
  • Training costs for employees involved in security and compliance
  • Documentation costs to create and maintain evidence and policies
  • Maintenance costs to operate and continuously update the ISMS

The total cost depends on the TISAX® level you aim to achieve, whether an ISMS is already in place, and how many internal resources are available.

Before starting implementation, it helps to assess how much foundational work is still required. This creates clarity on effort, priorities, and the overall investment needed to meet TISAX® requirements.

Ongoing costs and re-assessments

A certification on TISAX® is valid for three years and must be renewed afterward. A new assessment is required to maintain your label, and the associated costs should be factored into your overall planning.

During this period, no external audits take place. However, companies are required to continuously maintain their ISMS and conduct regular internal self-assessments. These help document improvements and prepare for the next audit.

If you cannot provide evidence of internal reviews and ongoing improvements during the re-assessment, the auditor may raise findings that can put your label at risk. This shows that long-term ISMS maintenance, not just initial certification, determines ongoing compliance.

What are the benefits of the certification on TISAX®?

TISAX® provides both operational and strategic advantages for companies in the automotive ecosystem.

Competitive advantages for automotive suppliers

Companies with TISAX® assessment results can participate more easily in OEM projects. Many contracts require proof of compliance before collaboration begins.

Risk reduction and compliance

A structured security framework reduces the likelihood of incidents and improves overall resilience. It also helps align with regulatory expectations.

ROI of certification on TISAX®

The financial return of TISAX® certification cannot always be expressed as a fixed number. Factors such as company size, industry, and market conditions influence the overall ROI.

While initial investments can be significant, long-term benefits include reduced audit effort, improved efficiency, and stronger partner trust. What remains clear is the long-term impact: increased trust, access to new markets, and more stable customer relationships all contribute to measurable business value over time.

11_icta_top

Strengthen your information security posture


From building an ISMS to risk management and employee training, DataGuard helps you secure what matters most.

What happens if you do not obtain certification on TISAX®?

Certification on TISAX® is not a legal requirement. In practice, however, it is often a prerequisite for working with OEMs. Without it, companies face a higher risk of falling short of industry security standards and losing competitiveness.

Rapid regulatory changes, increasing cyber threats, and stricter customer requirements require continuous ISMS maintenance aligned with TISAX®. Without certification, companies risk not only losing business opportunities but also exposing themselves to higher security risks in their operations.

Business risks

Without a recognized assessment, organizations may struggle to demonstrate adequate security levels. This can impact customer relationships.

Lost opportunities in the automotive supply chain

Many OEMs require TISAX® as a baseline. Without it, companies may be excluded from tenders or partnerships.

 

TISAX® vs ISO 27001: What is the difference?

Key similarities

TISAX® is based on ISO 27001 and follows a similar approach to information security management. Both frameworks confirm that organizations meet defined requirements for building, implementing, and operating an Information Security Management System.

In both cases, the focus lies on structured risk management, clearly defined processes, and continuous improvement of security controls. This creates a consistent and auditable approach to protecting sensitive information.

Key differences

While ISO 27001 is a globally applicable standard, TISAX® is specifically tailored to the automotive industry. It translates general information security principles into concrete requirements that reflect the risks and expectations within automotive supply chains.

In addition to information security, TISAX® also covers areas such as prototype protection and data protection. These domains address industry-specific risks that are not part of ISO 27001 in the same level of detail.

Another key difference is the outcome: ISO 27001 results in a formal certificate, while TISAX® uses a label system with results shared through the ENX platform.

When companies should use both

An ISO 27001 certification can simplify preparation for TISAX® by providing an established ISMS foundation. However, it does not replace a TISAX® assessment. Companies operating in the automotive sector, especially suppliers, typically need TISAX® to meet OEM requirements, and benefit from combining both frameworks to cover global standards and industry-specific expectations.

What are the next steps to achieve certification on TISAX®?

A structured roadmap helps you move efficiently toward a successful TISAX® assessment. Each step builds on the previous one and ensures that your organization meets the required security standards in a controlled and traceable way.

Define scope and requirements

Start by determining which parts of your organization are included in the assessment. This typically depends on customer requirements, the type of data you handle, and your role in the supply chain. A clearly defined scope ensures that all relevant systems, processes, and locations are considered from the beginning.

Perform gap analysis

Compare your current setup against the VDA ISA requirements. This helps identify missing or insufficient controls and highlights where adjustments are needed. A structured gap analysis provides a clear baseline for planning your implementation.

Implement required controls

Close the identified gaps by introducing or strengthening technical and organizational measures. At this stage, it is important to ensure that controls are not only defined but also operational and supported by proper documentation.

Start the assessment process

Select an approved audit provider and initiate the formal assessment. This includes submitting your scope, undergoing the audit, and preparing for the validation of your implementation and documentation.

How DataGuard supports certification on TISAX®

DataGuard supports companies throughout the TISAX® journey. The platform combines structured workflows with expert guidance to help implement and maintain required controls.

You gain visibility into your compliance status, align your processes with VDA ISA requirements and reduce manual effort during preparation and audits.

Frequently asked questions

How long does Certification on TISAX® take?

Is TISAX® mandatory for automotive suppliers?

Can small companies obtain Certification on TISAX®?

How often does TISAX® need to be renewed?

Can TISAX® replace ISO 27001?

🏢 Organization Schema Preview (Development Only)
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "www.dataguard.com#organization",
      "name": "DataGuard",
      "legalName": "DataCo GmbH",
      "description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
      "foundingDate": "2018",
      "taxID": "DE315880213",
      "logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
      "url": "www.dataguard.com",
      "email": "info@dataguard.de",
      "telephone": "+49 89 452459 900",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Sandstrasse 33",
        "addressLocality": "Munich",
        "addressRegion": "Bavaria",
        "postalCode": "80335",
        "addressCountry": "Germany"
      },
      "sameAs": [
        "https://www.linkedin.com/company/dataguard1/",
        "https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
        "https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
      ]
    }
  ]
}

✅ Organization schema markup for "DataGuard" has been injected into the document head.