Over 6,000 automotive suppliers across Europe are currently registered in the ENX portal for TISAX assessments. If your company handles sensitive data for OEMs like BMW, Volkswagen, Audi, or Mercedes-Benz, you almost certainly need TISAX certification — or you will soon. Increasingly, automotive manufacturers are making it a hard gate in procurement contracts, not a nice-to-have checkbox.
TISAX (Trusted Information Security Assessment Exchange) was developed by the German Association of the Automotive Industry (VDA) in 2017 and is now the de facto information security standard for the global automotive supply chain. It builds on VDA ISA (Information Security Assessment), which itself draws heavily from ISO/IEC 27001, but adds automotive-specific controls around prototype protection and connected vehicles. Think of it as ISO 27001 with a torque wrench applied specifically to supplier relationships.
This guide covers everything: the current TISAX requirements, how the audit process actually works in 2026, realistic cost ranges, how TISAX stacks up against ISO 27001, and where to focus your preparation effort to avoid nasty surprises during the assessment.
What TISAX Actually Certifies — and What It Doesn't
First, a precision point that trips up a lot of people. TISAX doesn't issue a public certificate in the traditional sense. You receive an assessment result shared confidentially through the ENX portal, accessible only to the specific companies you authorize. Your OEM partner requests access; you grant it. Nothing gets published on a registry anyone can browse.
The assessment result covers three potential scope areas, each requiring separate evaluation:
- Information with high protection needs — general sensitive business data, contracts, pricing, technical specs
- Prototype protection — physical and logical security for prototype vehicles, parts, and test data
- Connection to the infrastructure of third parties — handling of customer IT environments, remote access to partner systems
Most first-time TISAX participants only pursue the first scope. Prototype protection audits are significantly more involved — they include physical security walkthroughs, which means your facilities get physically inspected, not just your policy documents.
TISAX Assessment Levels: AL1, AL2, AL3
The TISAX framework defines three assessment levels (AL), and your OEM partner will specify which level they require:
Assessment Level 1 (AL1)
Self-assessment only. You complete the VDA ISA questionnaire internally, and the result is shared with your partner without any external audit validation. AL1 is increasingly rare in real supplier relationships — most OEMs have moved past accepting self-assessments after a string of supply chain breaches in the early 2020s.
Assessment Level 2 (AL2)
This is the most common requirement. An accredited TISAX auditor conducts a plausibility check of your self-assessment responses, typically combining document review with a site visit (or remote equivalent since the 2023 ENX remote assessment guidelines). AL2 covers the majority of Tier 1 and Tier 2 suppliers handling standard sensitive information.
Assessment Level 3 (AL3)
Full on-site audit with document review, interviews, and technical testing. Required when you're dealing with very high protection needs — think highly confidential prototype data, or when you have direct connectivity to an OEM's production systems. AL3 audits are thorough, expensive, and time-consuming. Plan for them accordingly.
Core TISAX Requirements in 2026
The current VDA ISA version (6.0.2, effective from 2024) organizes requirements into chapters that map closely to ISO 27001 Annex A but with notable additions. Here are the areas where automotive suppliers consistently find gaps during pre-assessments:
Information Asset Management
You need a complete inventory of information assets — not just IT assets, but information classified by sensitivity. This includes understanding where customer data (OEM intellectual property, technical drawings, pricing data) lives across your environments. If your asset inventory only captures hardware and software, you're already behind. Tools like Cloud Inventory can automate discovery across cloud environments, which matters when your data is spread across Azure, AWS, or on-premises systems.
Access Control and Identity Management
Least-privilege access, multi-factor authentication for all external access, and documented access review processes are mandatory. The auditors will ask to see evidence of periodic access reviews — not just a policy stating you do them. Screen captures from quarterly reviews, ticket records, user provisioning/deprovisioning logs. This is where many suppliers fail their first AL2 attempt: great policies, zero documented evidence.
Incident Detection and Response
VDA ISA requires defined incident response procedures with specific response time targets. You need to show that security events are logged, monitored, and escalated according to a documented playbook. Automated alerting, SIEM integration, and defined escalation paths are expected at AL2 and above. Our Vulnerability Management solution helps teams maintain continuous visibility into their risk posture between audit cycles, so you're not scrambling to close findings two weeks before an assessment.
Supplier Management
This one catches companies off guard. TISAX requires you to manage the information security of your own suppliers — the sub-suppliers who handle OEM data downstream. You need a supplier information security assessment process, contractual clauses covering data handling, and evidence that you've actually reviewed your critical suppliers. The supply chain goes both ways.
Cryptography and Key Management
Encryption at rest and in transit for sensitive data isn't optional. But VDA ISA goes further — it requires documented cryptographic policies, defined key management procedures, and periodic review of cryptographic algorithm strength. Using TLS 1.0 anywhere in your environment will be flagged immediately.
Physical Security (Critical for Prototype Scope)
If you're pursuing prototype protection scope, brace yourself. TISAX auditors will conduct physical walkthroughs of your facilities. They're looking for access control systems (badge readers, CCTV, visitor logs), clean desk policies in effect, secure disposal of prototype-related materials, and physical separation of prototype work areas. This isn't just an IT audit — it crosses into physical security in a serious way.
TISAX Certification Cost: Realistic Numbers for 2026
Let's talk money, because the official documentation is deliberately vague on this. Here's what the actual cost structure looks like:
ENX Registration Fee
Registering your company in the ENX portal costs between €200 and €500 depending on your company size tier. This is the entry fee — you pay it before anything else happens.
Audit Body Fees
The bulk of TISAX certification cost comes from the accredited audit provider. ENX accredits specific providers (Dekra, TÜV Rheinland, Bureau Veritas, and others). For AL2 with a single scope and single location, expect to budget €8,000–€18,000 for the audit engagement. AL3 audits can easily run €25,000–€50,000+ depending on complexity and number of sites. Remote assessments (permitted under the 2023 guidelines) typically cost 20–30% less than full on-site audits.
Internal Preparation Costs
This is often underestimated. If you're starting from scratch — no existing ISMS, no ISO 27001 foundation — you're looking at 6–12 months of internal effort. Consultant-assisted preparation typically adds €15,000–€40,000 in external consulting fees. If you already have ISO 27001, you can typically reduce preparation effort by 40–60% because the control frameworks overlap significantly.
Remediation and Follow-Up
First-time assessments frequently surface findings that require remediation before the result is shared. Budget for a remediation cycle — typically 3–6 months of additional work and potentially a follow-up audit session. Factor this into your project timeline from day one.
TISAX Certification vs ISO 27001: The Real Comparison
This comes up constantly: do you need TISAX if you already have ISO 27001? Or vice versa? The honest answer: they serve different purposes, and having one doesn't replace the other.
ISO 27001 is a general-purpose information security management standard — applicable to any industry, any organization size, publicly certifiable, globally recognized. TISAX is automotive-sector specific, confidential by design, and required specifically for access to the VDA/ENX ecosystem.
The control overlap is substantial — roughly 70–80% of TISAX requirements have direct ISO 27001 equivalents. But TISAX adds controls that ISO 27001 doesn't cover in the same depth: prototype protection, VDA ISA's specific questionnaire structure, and the ENX-managed sharing mechanism. Conversely, ISO 27001 requires a formal ISMS management system and certification body accreditation under ISO/IEC 17021 — TISAX uses its own accreditation scheme through ENX.
If you're serving automotive OEMs, you need TISAX. ISO 27001 helps you get there faster and demonstrates security maturity to non-automotive customers simultaneously. Pursue both if you can justify the investment.
For companies already managing cloud security posture alongside their compliance programs, Compliance solutions that map controls across frameworks save significant duplication of effort when preparing for both standards simultaneously.
The TISAX Auditor Certification Path
If you're planning to build internal TISAX competency — or you're a consultant expanding into automotive security — the TISAX auditor certification route is worth understanding. ENX manages the auditor accreditation process, and accredited auditors must demonstrate competency through a combination of ISO 27001 Lead Auditor qualification, automotive industry experience, and ENX-specific training modules. The full path typically takes 12–18 months and involves practical assessments observed by senior ENX-accredited auditors.
For internal use, you don't need TISAX auditor certification yourself — but having team members who've completed the ENX Associate Auditor training significantly improves your internal pre-assessment quality.
Common Failure Points in TISAX Assessments
After reviewing numerous assessment reports, the failures cluster around a handful of root causes. Evidence gaps top the list — policies exist but implementation evidence doesn't. Scope creep comes second: organizations underestimate which systems and locations process OEM data, and the audit covers systems they hadn't prepared. Third is supplier management: virtually every organization underestimates the sub-supplier documentation requirement.
A practical preparation approach: run an internal gap assessment against VDA ISA 6.0.2 at least six months before your scheduled audit. Use that gap assessment to drive remediation priorities. Don't wait for the auditor to discover your evidence gaps — that's expensive and delays your result by months.
Automated scanning tools help here. Policy-as-Code enforcement means your cloud configurations stay compliant continuously rather than drifting between audit cycles. Similarly, Secret Detection across your codebase prevents the kind of credential exposure that would be a critical finding in any TISAX assessment.
TISAX in 2026: What's Changed and What's Coming
VDA ISA 6.0.2 introduced stronger requirements around AI systems and connected vehicle data — a reflection of how the automotive industry has evolved. If your company processes data from ADAS systems, telematics platforms, or vehicle connectivity services, expect additional scrutiny around AI data governance and edge security controls.
ENX has also signaled upcoming updates to the remote assessment guidelines, potentially expanding the scope of what can be assessed remotely versus requiring physical presence. This is particularly relevant for multi-site suppliers who previously faced significant cost pressure from on-site assessment requirements at each location.
The broader trend is clear: TISAX scope is expanding beyond traditional IT security. Physical security, AI governance, supply chain visibility — the standard is maturing alongside the industry it protects. Companies that treat TISAX as a one-time certification project rather than an ongoing information security program will find themselves scrambling to keep up with each VDA ISA revision.
If you're building or scaling a compliance program that needs to handle TISAX alongside other frameworks, SECRAILS provides the technical foundation — continuous monitoring, automated evidence collection, and policy enforcement — that makes multi-framework compliance sustainable rather than exhausting. The goal isn't to pass an audit. It's to run a security program that makes audits a formality.

