verified_user
Standardful
Homechevron_rightStandardschevron_rightTISAX
ActiveInternational Standardupdate Last Updated: Apr 2024

TISAX

Trusted Information Security Assessment Exchange — VDA Information Security Assessment

apartmentPublishing Organization:German Association of the Automotive Industry (VDA) / ENX Association

Standard Introduction

TISAX (Trusted Information Security Assessment Exchange) is an information security assessment standard developed by the German Association of the Automotive Industry (VDA) and administered by the ENX Association. Based on the VDA Information Security Assessment (ISA) questionnaire, it provides a standardized approach to evaluating information security in the automotive supply chain.

TISAX enables mutual recognition of security assessments between automotive manufacturers and their suppliers, eliminating costly redundant audits. With over 10,000 companies registered on the ENX portal, TISAX has become the de facto standard for information security in the European automotive industry and is increasingly adopted globally by OEMs and their supply chains.

directions_car

Automotive-Specific

Purpose-built for the automotive supply chain, based on VDA ISA (Information Security Assessment) questionnaire adapted from ISO 27001/27002 with automotive-specific requirements.

swap_horiz

Mutual Recognition

Assessment results are shared via the ENX portal, enabling mutual recognition between automotive OEMs and suppliers — eliminating redundant audits across the supply chain.

verified

Three Assessment Levels

Level 1 (self-assessment), Level 2 (remote verification for high protection), and Level 3 (on-site inspection for very high protection needs such as prototype data).

list_alt VDA ISA Assessment Modules

  • Information Security — based on ISO 27001/27002 controls
  • Prototype Protection — physical and organizational protection of prototypes
  • Data Protection — GDPR-aligned personal data processing requirements
  • Availability — IT and OT system availability requirements (new in ISA 6.0)
  • Third-party connection security
  • Incident and crisis management
  • Human resource security and awareness
  • Asset management and classification

Who Needs to Comply?

groups

Automotive suppliers, engineering partners, and service providers that handle confidential information from OEMs such as Volkswagen, BMW, Daimler, and other VDA members. Required for participation in most European automotive supply chains.

Key Requirements

1

VDA ISA Self-Assessment

Complete the VDA Information Security Assessment questionnaire covering all applicable modules. Assess maturity levels (0-5) for each control objective and identify gaps.

2

Assessment Provider Audit

Engage an ENX-approved audit provider to conduct the assessment at the required level. Level 3 requires comprehensive on-site inspection and in-person interviews.

3

Prototype Protection

If handling prototype components, vehicles, or design data, implement specific physical security measures including restricted areas, visitor controls, photography bans, and logistics security.

4

Label Maintenance

TISAX labels are valid for three years. Organizations must undergo re-assessment before expiration to maintain their label and supply chain eligibility.

Penalties & Enforcement

warning

No direct legal penalties — TISAX is an industry-driven requirement. However, failure to obtain or maintain a valid TISAX label effectively disqualifies suppliers from working with major European automotive OEMs, resulting in loss of business relationships and contracts.

Official Documentation

View All

Implementation Timeline

new_releases
2017
TISAX established by VDA and ENX Association
update
2020
VDA ISA 5.0 released with expanded controls
sync
Oct 2022
VDA ISA 5.1 aligned with ISO 27001:2022
check_circle
Apr 2024
VDA ISA 6.0 effective with new availability module
verified
2025
All assessments conducted under VDA ISA 6.0

Related Categories