TISAX (Trusted Information Security Assessment Exchange) is the automotive industry standard for proving information security: manufacturers and suppliers are assessed against the VDA ISA catalogue and share results via a common platform — one assessment recognised by all participants instead of individual audits per customer.
Anyone working for automotive manufacturers or processing their confidential information can hardly avoid TISAX: many OEMs require a valid label as a condition for collaboration.
How TISAX works
The basis is the VDA ISA catalogue, closely aligned with ISO 27001 and extended by modules for prototype protection and data protection. Depending on the protection needs of the information processed, assessment levels apply: from self-assessment with plausibility checks to on-site audits by an approved audit provider. The result are labels valid for three years, shared via the ENX platform.
The path leads through a lived ISMS: risk management, policies, access control, physical security, supplier governance — plus the automotive-specific requirements, such as handling prototypes and camouflaged vehicle material. Maturity levels count: processes must not only exist but demonstrably work.
TISAX in practice
- One assessment for many customers: result sharing replaces audit series.
- Three assessment levels depending on protection needs — up to on-site audits.
- Network security pays in directly: segmentation, access control, monitoring.
- Plan preparation realistically: from ISMS build-up to label often takes months.