An independent overview from DQS, an accredited certification body.

TISAX® (Trusted Information Security Assessment Exchange) is the established information security assessment scheme for the automotive industry. It enables automotive OEMs, suppliers, and service providers to demonstrate their capabilities in securely handling confidential information, ensuring the required availability of goods and services, protecting classified prototypes, and safeguarding personal data. TISAX® is relevant across the automotive supply chain, including OEMs, Tier 1 and Tier 2 suppliers, engineering service providers, IT and software providers, logistics companies, and aftermarket organizations.

A successful TISAX® assessment demonstrates that the required capabilities are implemented and effective. The assessed locations are then awarded the corresponding TISAX® labels. Unlike traditional certification schemes, TISAX® does not issue certificates. The assessments are conducted by audit providers approved by the ENX Association, and the resulting TISAX® labels can be shared with other participants in the automotive ecosystem through the ENX Portal.

The TISAX® labels determine which requirements of the VDA Information Security Assessment (ISA) catalog apply to an organization. For supplier management, organizations can specify the combination of TISAX® labels required from each supplier. These requirements can be aligned with the supplier’s responsibilities, the services provided, and the information or prototype assets entrusted to them. This enables a risk-based approach in which TISAX® requirements are tailored to the specific role and responsibilities of each supplier.

Already operating in the automotive supply chain and required to demonstrate information security?

If your organization handles protected information for automotive customers and you are preparing for a TISAX® assessment, our dedicated assessment page has everything you need – from process overview to a personalized quote.

Go to TISAX® As­sess­ment with DQS

Information Security Assessment catalog

Beginning in 2027, the VDA will transition the ISA catalog to an annual release cycle. Each new edition will be published around the middle of the year and will become the current ISA version at the beginning of the following year.

From January onward, new assessments can only be offered according to the latest ISA version. Assessments that were already ordered based on the previous ISA version may still be conducted during a limited transition period. However, the assessment opening meeting must take place no later than the end of March.

The annual release cycle allows the automotive industry to respond more quickly and agilely to the evolving threat landscape, particularly as AI accelerates the development of new technologies, attack methods, and associated information security risks.

dqs-man looks at the three-dimensional concept of a car in software
Loading...

Want to know what is new in ISA 2027?

If your organization is already in conformity with the current ISA catalog and you want to understand what changes and adaptations ISA 2027 will bring, we have prepared the following blog posts for you:

Key Facts about TISAX® at a Glance

Full TitleTrusted Information Security Assessment Exchange (TISAX®)
Published byENX Association on behalf of the German Association of the Automotive Industry (VDA).
First Published2017
Management System TypeInformation security management system, with automotive-specific controls and protection-needs orientation.
Applicable toOrganizations handling automotive information assets – including OEMs, tier 1 and tier 2 suppliers, engineering service providers, IT and software vendors, logistics providers, and aftermarket organizations.
CertifiableTISAX® is an assessment scheme, not a certification scheme. A successful assessment results in one or more TISAX® labels exchanged via the ENX Portal; it is not an ISO-style certificate.
RequirementsISA catalog defines requirements for specific TISAX® labels.

 

Context and Drivers for TISAX®

Automotive Information Security and Prototype Protection

The automotive industry exchanges large volumes of sensitive technical, commercial, and personal data across its supply chain. Protecting prototypes, designs, supplier-shared technical packages, and customer personal data is a long-standing concern. TISAX® evolved from earlier VDA initiatives to provide a common assessment that OEMs and suppliers can rely on without repeated bilateral audits. As cyber threats and regulatory expectations have evolved, the VDA ISA has been progressively updated to address them.

Role in the supply chain

Availability of goods and services was established as a key protection objective alongside confidentiality, reflecting the different roles and responsibilities that suppliers may have within the automotive industry. The TISAX® label structure distinguishes between confidentiality and availability at both the High and Very High Protection levels. This enables customers to define and assess supplier capabilities more precisely based on the specific confidentiality and availability requirements associated with each supplier’s role.

Mutual Recognition Through the ENX Portal

TISAX® is built around mutual recognition: an organization commissions an assessment once and shares the results with participating automotive customers via ENX Portal, in line with the rules of the scheme. This reduces duplicative audits across customers and supports informed sourcing decisions by procurement and information security functions within OEMs and tier 1 suppliers.

Information Security (ISA module)

The Information Security catalog covers organizational and technical controls aligned with ISO/IEC 27001 concepts: information security policies, organization of information security, human resource security, asset management, access control, cryptography, physical and environmental security, operations security, communications security, system acquisition, supplier relationships, incident management, business continuity, and compliance.

Prototype Protection (ISA module)

The Prototype Protection catalog sets out specific controls for the handling of physical prototypes, test vehicles, components in development, and related sensitive assets – including site security, transport protection, testing in public, and exhibition handling. This part of the ISA distinguishes TISAX® from generic information security assessment schemes.

Data Protection (ISA module)

The Data Protection catalog covers 12 controls aligned with privacy expectations such as those of the GDPR, addressing topics such as records of processing, data subject rights, breach handling, processor management, and international transfers.

Assessment Levels and Protection Needs

TISAX® defines three assessment levels – AL 1 (self-assessment, very limited), AL 2 (remote assessment), and AL 3 (on-site assessment) – calibrated to the protection needs of the assessed scope.

 

Target Groups and Application Areas for TISAX®

TISAX® is intended for any organization in the automotive ecosystem that handles protected customer information – confidential technical or commercial information, prototypes, personal data, or other information identified by automotive customers as requiring controlled handling. Typical participants include OEMs, tier 1 component suppliers, tier 2 component and sub-component suppliers, engineering service providers (design and validation services), IT service providers and software vendors, logistics and warehousing providers handling automotive shipments, and aftermarket and service organizations.

Automotive customers typically require a current TISAX® label as a precondition for awarding contracts involving protected information. TISAX® assessments support informed sourcing decisions by procurement and information security functions in automotive customer organizations and provide supply-chain partners with a consistent reference for information security maturity.

Organizations outside the automotive sector typically use ISO/IEC 27001 or other sector-specific information security schemes rather than TISAX®. Where an organization serves both automotive and non-automotive customers, ISO/IEC 27001 certification and TISAX® labels are often maintained in parallel, with significant overlap in the underlying controls.

Standards Related to TISAX®

ISO/IEC 27001 (ISMS)

The ISA catalog builds on the conceptual structure of ISO/IEC 27001, and its Annex A controls, adapted to the automotive context. ISO/IEC 27001 is an internationally recognized certifiable management system standard for information security; The two are related but not formally equivalent: ISO/IEC 27001 certification does not automatically result in TISAX labels although certification and labels typically reinforce each other for organizations that hold both.

ISO/IEC 27701 (Data Protection)

ISO/IEC 27701 is the privacy information management extension to ISO/IEC 27001. It is conceptually adjacent to the Data Protection part of the ISA but is structured as a certifiable extension of ISO/IEC 27001 rather than as part of an automotive scheme. Organizations operating GDPR-relevant scopes may find ISO/IEC 27701 useful alongside TISAX®.

IEC 62443-2-1 (Security program requirements for IACS owners)

IEC 62443-2-1 defines the requirements for establishing and maintaining a cybersecurity management system for Industrial Automation and Control Systems (IACS). It covers areas such as governance, risk assessment, asset management, access control, incident response, backup, change management, supplier management, and continuous improvement. Its objective is to ensure that IACS asset owners manage cybersecurity systematically throughout the lifecycle of their operational technology environment.

ENX VCS (Vehicle Cybersecurity Scheme)

ENX VCS is the vehicle cybersecurity scheme operated by the ENX Association, addressing UN Regulation No. 155 (cybersecurity management) and related ISO/SAE 21434 expectations for the automotive industry. ENX VCS and TISAX® are both ENX schemes but cover different topics – VCS focuses on vehicle cybersecurity governance and assessments of suppliers’ cybersecurity management systems for vehicle type approval, while TISAX® focuses on information security at the supplier’s site.

Differentiation from Generic Cybersecurity Frameworks

Frameworks such as the NIST Cybersecurity Framework and the U.S. CMMC program address adjacent topics but apply in different contexts (U.S. federal contracts, voluntary frameworks). They are not formally recognized as equivalent to TISAX®, and automotive customers generally rely on TISAX® labels rather than alternative frameworks.

Your organization handles protected information for automotive customers. Are you now preparing for a TISAX® assessment?

Learn more on our dedicated TISAX® page.

TISAX® As­sess­ment with DQS

About DQS as a certification body

This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:

  • One of Germany’s first management system certifiers – DQS issued its first certificate in
  • Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
  • Approved as a TISAX® und VCS audit provider by the ENX Association and accredited for related standards including ENX VCS, ISO/IEC 27001 and IATF – so automotive organizations can be served across TISAX assessment and information-security certification from a single provider.
  • Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.

The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body’s official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 3 June 2026.

Frequently Asked Questions about TISAX®

Is TISAX® mandatory?

TISAX® is a voluntary assessment scheme. However, automotive customers – OEMs and tier 1 suppliers – typically require a current TISAX® label as a condition of awarding contracts that involve protected information. In practice, TISAX® is therefore a commercial requirement for many organizations in the automotive supply chain.

Is TISAX® a certification?

No. TISAX® is an assessment scheme, not a certification scheme. A successful assessment results in a TISAX® label (or labels) exchanged via ENX Portal, rather than an ISO-style certificate. The distinction reflects the mutual-recognition design of the scheme.

How long is a TISAX® label valid?

TISAX® labels have a defined validity period, typically three years from the date of issue, subject to the scheme’s rules. Organizations need to schedule reassessment ahead of label expiry to maintain continuous label status. Some customers expect specific labels to remain current as a condition of ongoing business.