Today’s automotive industry is a global, highly complex web of relationships between automakers (OEMs) and thousands of their suppliers and subcontractors. In this ecosystem, data - from new model designs to prototypes to production data - is one of the most valuable and protected assets. Their leakage could lead to catastrophic financial losses and loss of competitive advantage. To ensure a uniform and high level of information security throughout the supply chain, the German Association of the Automotive Industry (VDA) created a standard that has become a de facto mandatory “passport” to business in the industry: TISAX.
TISAX (Trusted Information Security Assessment Exchange) is a standardized mechanism for assessing and exchanging information security audit results. For any supplier that wants to work with German automotive giants such as Volkswagen, BMW, Audi and Mercedes-Benz, having the TISAX label has ceased to be an option and has become a hard business requirement. This step-by-step guide will explain what TISAX is, what its requirements are, what the certification process looks like, and how solid preparation, based on experience with ISO 27001, is the key to success.
Shortcuts
- What is TISAX and why has it become a mandatory safety standard in the automotive industry?
- What is the relationship between TISAX and the ISO 27001 international standard?
- Who in the automotive supply chain must be TISAX certified?
- What are the different assessment levels (Assessment Levels) in TISAX and what do they depend on?
- What are the key areas and requirements that are subject to a TISAX audit?
- What is the step-by-step process for preparing a company and obtaining the TISAX label?
- What is involved in registering on the ENX platform and selecting an accredited audit provider?
- How to conduct a self-assessment and identify gaps against VDA ISA requirements?
- How much time and resources should I allocate to prepare for a TISAX audit?
- What are the most common mistakes and problems that companies encounter in the certification process?
- How to maintain compliance and prepare for reassessment after three years?
- How can nFlo’s experience in ISO 27001 implementations help your company successfully prepare for an audit and achieve TISAX certification?
What is TISAX and why has it become a mandatory safety standard in the automotive industry?
TISAX, or Trusted Information Security Assessment Exchange, is a standardized information security assessment and exchange system dedicated to the automotive industry. It was developed by the German Automotive Industry Association (VDA) to create a common, uniform standard for the entire supply chain. TISAX is not a new security standard, but a platform and mechanism that builds on the VDA ISA (Information Security Assessment) requirements catalog, which in turn is a development of the international ISO/IEC 27001 standard.
The reason why TISAX has become a mandatory standard in practice is the attitude of Germany’s largest automakers (Original Equipment Manufacturers, OEMs). Companies such as the Volkswagen Group, BMW Group and Mercedes-Benz Group, in their contractual requirements, outright demand that their suppliers and business partners have a current and relevant TISAX label. The absence of such certification is tantamount to the inability to establish or continue cooperation. OEMs want to be assured that their valuable data - designs, prototypes, production data - is safe at every stage of the supply chain, from the largest Tier 1 supplier to the smallest subcontractor.
Instead of conducting hundreds of individual audits with each of their suppliers (which was inefficient and costly), OEMs outsourced this task to a neutral third party. The TISAX platform, managed by the ENX Association, allows a single, standardized audit to be conducted by an accredited supplier. The result of this audit (the so-called “TISAX label”) is then made available on the platform and can be easily verified by all business partners. This has created a consistent, transparent and efficient system that has become a “driver’s license” for any company wishing to operate in the European automotive industry.
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
What is the relationship between TISAX and the ISO 27001 international standard?
The relationship between TISAX and ISO/IEC 27001 is very close and fundamental. TISAX is not a competing standard, but rather an automotive-specific development and refinement of the requirements contained in ISO 27001. A company that already has an ISO 27001-compliant Information Security Management System (ISMS) in place and certified has a much easier path to TISAX certification.
The requirements catalog against which the TISAX audit is conducted is called VDA ISA (Information Security Assessment). It was developed by the German Association of the Automotive Industry (VDA) and is largely based on Annex A of ISO 27001, which lists 114 (in the older version) or 93 (in the newer 2022 version) security features. The VDA ISA takes this structure and adds additional, specific requirements that are key to the automotive industry.
These additional requirements mainly concern three areas. First, protection of prototypes, i.e., the physical and logical security of parts, components and entire vehicles in the pre-production phase. Second, the protection of personal data in the context of compliance with RODO (GDPR). Third, in some cases, integration with OEM production systems. So you could say that TISAX is “ISO 27001 on steroids,” tailored to the unique risks and needs of the automotive sector. Being ISO 27001 certified does not exempt you from the TISAX label, but it is an excellent starting point and proof of your organization’s maturity in the area of information security, covering much of the VDA ISA requirements.
Who in the automotive supply chain must be TISAX certified?
The requirement for TISAX certification applies to a very broad spectrum of companies operating in the automotive supply chain. Basically, any organization that processes confidential information from one of the German automakers (OEMs) as part of its operations will sooner or later be asked to demonstrate the appropriate TISAX label.
In the first instance, this requirement applies to Tier 1 direct suppliers, i.e., companies that supply OEMs with finished components, systems and modules. These are the largest players who have direct access to critical design and manufacturing data, so the highest level of security is required of them. However, this obligation cascades down the supply chain.
Tier 1 suppliers, in order to meet the requirements of their customers, must ensure that their sub-suppliers (so-called Tier 2, Tier 3, etc.) also meet the relevant standards. Therefore, the requirement for TISAX certification also applies to smaller companies that produce individual parts, raw materials or provide processing services.
Importantly, TISAX is not limited to manufacturing companies. The obligation also applies to a wide range of service providers that have access to automotive industry data. These include IT companies (software providers, cloud services, IT support), logistics and transportation companies, marketing agencies, consulting firms and even law firms. If any company under contract with an automotive customer processes its confidential data, it may be required to undergo a TISAX audit.
What are the different assessment levels (Assessment Levels) in TISAX and what do they depend on?
The TISAX system defines three different Assessment Levels (AL), which determine the level of rigor and depth of the audit. The choice of the appropriate level is not arbitrary - it is imposed by the business partner (OEM or upstream supplier) and depends on the level of sensitivity of the data to which the company will have access. The more critical the data, the higher the required level of assessment.
Level 1 (AL 1): “Normal” (assessment based on self-assessment) This is the lowest level, which in practice is rarely sufficient for business partners. Assessment at this level is based solely on a self-assessment (self-assessment) completed by the company. The company itself declares to what extent it meets the requirements of the VDA ISA catalog. There is no external verification by an auditing body. AL Level 1 can only be used for information exchanges with a very low level of confidentiality.
Level 2 (AL 2): “High” (remote assessment) This is the most common level. Assessment at this level, in addition to self-assessment, includes remote verification by an accredited auditor. The auditor interviews employees (e.g., via video conference) and asks them to provide evidence (documents, policies, screenshots of system configurations) to verify the veracity of the self-assessment statements. This is a full-fledged audit, but conducted without a physical visit to the company’s premises.
Level 3 (AL 3): “Very High” (on-site assessment) This is the most stringent level, required for access to data with the highest degree of confidentiality, such as design data, prototype data or sensitive personal data. An AL Level 3 assessment, in addition to a self-assessment, requires a detailed on-site audit at the company’s physical locations. The auditor personally verifies the safeguards implemented, both logical and physical (such as access control to server rooms), and conducts face-to-face interviews with personnel.
What are the key areas and requirements that are subject to a TISAX audit?
The TISAX audit is conducted based on the VDA ISA (Information Security Assessment) catalog of questions and requirements. This catalog is structured and covers a wide range of information security topics, largely overlapping with the control domains from ISO 27001. The key areas to be assessed can be divided into several main groups.
The core area is Information Security, which is the core of the audit for any company. The requirements in this module are divided into chapters analogous to those in ISO 27001, and include:
-
Security Policy: Does the company have a documented and implemented Information Security Management System (ISMS)?
-
Security organizations: Are roles and responsibilities for security defined?
-
Human Resource Security: What are the processes for employee vetting, training and post-employment handling?
-
Asset management: Does the company have an inventory of information assets and are they properly classified?
-
Access control: How are system and data permissions managed (including the principle of lowest privilege)?
-
Cryptography: is data encryption used and how?
-
Physical and environmental security: How are server rooms and offices protected?
-
Operational Security: What are the procedures for change management, backups and vulnerabilities?
-
Communications security: How secure is the corporate network?
-
Incident management: Does the company have an incident response plan?
-
Legal Compliance: Does the company comply with legal requirements, including RODO?
In addition to this core module, depending on the partner’s requirements, the audit may include additional modules. The most important of these is Prototype Protection, which includes detailed requirements for securing physical and digital prototypes of parts, components and vehicles. Another module is Personal Data Protection, which verifies compliance with RODO. For some suppliers, a module on Third Party Connections may also be required, assessing the security of network connections to the OEM’s infrastructure.
What is the step-by-step process for preparing a company and obtaining the TISAX label?
The process of obtaining the TISAX label is structured and requires a company to prepare methodically and work closely with an accredited auditing body. It can be divided into several key, consecutive steps.
Step 1: Registration and selection of audit scope. The first formal step is to register the company on the official TISAX platform, managed by the ENX Association. During registration, you must define the scope of the assessment (assessment scope), that is, which company locations are to be audited. It is also necessary to define the assessment objectives (assessment objectives), i.e. which modules of the VDA ISA catalog will be audited (e.g. Information Security, Prototype Protection) and at what assessment level (AL 2 or AL 3). These objectives are usually defined by the business partner (OEM) that requires certification.
Step 2: Audit provider selection. After registering and defining the scope, the company selects an accredited audit provider from the list available on the ENX platform. This is an independent, third-party company that has been authorized to conduct TISAX audits. The company enters into a formal contract with the auditor to conduct the assessment.
Step 3: Self-Assessment. Before an external audit occurs, the company is required to conduct a detailed self-assessment based on the VDA ISA catalog. This involves an honest assessment of the extent to which the company complies with each requirement and documenting the evidence it has. The result of this self-assessment is the basis for further work and is shared with the auditor.
Step 4: Conduct an audit. Based on the self-assessment, the auditor conducts the actual assessment, according to the selected level (AL 2 - remotely, AL 3 - on-site). He verifies the company’s declarations, conducts interviews and analyzes evidence.
Step 5: Remediation plan and final evaluation. If the audit reveals any nonconformities, the company has a specified time to submit a corrective action plan. After its approval or after a successful audit, the auditor prepares a final report.
Step 6: Receive and share the label. Based on the report, the company receives a temporary and then permanent TISAX label on the ENX platform, which is valid for 3 years. From then on, the company can share the results of its assessment with selected business partners in a controlled manner, thus confirming its compliance with the standard.
What is involved in registering on the ENX platform and selecting an accredited audit provider?
The ENX platform is the centerpiece of the entire TISAX system. It is a secure web portal that is used to manage the entire assessment process, from registration, to exchanging information with the auditor, to sharing results with business partners. Registration on this platform is the first necessary formal step.
The registration process requires providing basic data about the company and designating a person responsible for the TISAX process. The key element here is to precisely define the scope of the assessment (scope). The company must decide whether the entire organization will be audited, or only selected locations or business units that work with the automotive industry. Defining the scope correctly is very important, as it has a direct impact on the cost and complexity of the audit.
Upon successful registration and payment of the annual platform fee, a company gains access to a list of accredited audit providers. These are independent, specialized audit firms (such as DEKRA, TÜV, BSI) that have undergone a rigorous accreditation process by the ENX Association and are the only ones authorized to conduct TISAX audits. The company must independently select one of these providers and contact them to establish terms and conditions and sign a contract to conduct the assessment.
Choosing an audit provider is an important decision. It is worth comparing the offers of several companies, paying attention not only to the price, but also to their experience in the industry, the availability of auditors who speak the local language, and feedback from other companies. Once you have formally “connected” with the selected auditor on the ENX platform, you can proceed to the next steps of the process, such as providing a self-assessment and scheduling audit appointments.
How to conduct a self-assessment and identify gaps against VDA ISA requirements?
Self-assessment (self-assessment) is a key and mandatory step in preparation for a TISAX audit. It is a process of in-depth, internal analysis aimed at an honest and objective assessment of the extent to which the company meets each of the requirements in the current version of the VDA ISA catalog. The result of this self-assessment is not only the basis for further work, but must also be shared with the selected auditor before the actual assessment begins.
The self-assessment process involves systematically going through all the checkpoints (questions) contained in the VDA ISA catalog. For each requirement, the company must rate its maturity level (maturity level) on a scale of 0 to 5, where 0 means “no/undefined process” and 5 means “optimized and continuously improved process.” In order to achieve a positive audit result, a company must reach a specific target maturity level for each requirement.
Conducting a reliable self-assessment requires the involvement of representatives from different departments within the company - IT, security, HR, as well as operational managers. For each requirement, evidence of its implementation should be collected and documented. This can include policies, procedures, instructions, screenshots of system configurations, vulnerability scan results or training records.
The purpose of this process is to identify gaps (gap analysis), i.e. those areas where the company does not meet the requirements or meets them inadequately. The result of the self-assessment should be a list of all identified nonconformities and weaknesses. Based on this list, the company creates a corrective action plan that specifies what steps need to be taken, who is responsible for them and by what date they are to be implemented in order to “close” all gaps before the external audit date.
How much time and resources should I allocate to prepare for a TISAX audit?
The time and resources needed to prepare for a TISAX audit can vary dramatically depending on several key factors. There is no one-size-fits-all answer, and the process can take anywhere from a few months to even more than a year. Realistic planning of the schedule and budget is crucial to the success of the project.
The main factor affecting time and cost is the company’s current level of information security maturity. If the company already has an implemented and well-functioning Information Security Management System (ISMS), such as one compliant with ISO 27001, the preparation process will be much shorter and easier. Many of the TISAX requirements will already be in place, and the work will focus on adapting to specific VDA ISA requirements (e.g., protection of prototypes) and preparing documentation. In such a scenario, preparation can take 3 to 6 months.
However, if a company is starting from scratch, with no formal policies, procedures or dedicated security team, the process will be much longer and more labor-intensive. It requires building an entire security management system from scratch. In this case, a realistic time horizon is 9 to 18 months.
Other factors affecting the process are the size and complexity of the organization, as well as the scope of the audit (number of locations, modules required). In terms of resources, the company must budget for external audit costs, which are paid to the audit firm. Internal costs, i.e. the time of employees involved in the project (usually a dedicated project coordinator and representatives from IT, HR and other departments) should also be taken into account. In many cases, especially in companies without much experience in this area, it is also necessary or highly recommended to hire an external consulting firm to help conduct a gap analysis, prepare documentation and implement the necessary safeguards, which is also an important part of the budget.
What are the most common mistakes and problems that companies encounter in the certification process?
The TISAX certification process, while well-structured, is fraught with potential pitfalls. Being aware of the most common mistakes allows companies to avoid them and get through the audit more smoothly.
One of the most common problems is underestimating the scale and complexity of a project. Many companies, especially smaller ones, treat TISAX as a simple “checklist” that can be completed quickly. In reality, it is a comprehensive management system audit that requires profound changes in the organization’s processes and culture. Overly optimistic assumptions about the time and resources needed for preparation lead to rushed, superficial implementations and, ultimately, a negative audit result.
Another common mistake is a lack of commitment from top management. If management treats TISAX solely as an “IT department problem,” the project is doomed to failure. Implementing an effective information security system requires support, budget and decisions at the strategic level. Lack of this support leads to problems with resource allocation and lack of cooperation between departments.
On a substantive level, a common problem is an unreliable self-assessment. Companies tend to be overly optimistic about their level of maturity, leading to unpleasant surprises during an external audit. Other common mistakes include incomplete documentation (lack of policies, procedures, evidence of application), inadequate management of vendor vulnerabilities and risks, and deficiencies in training and building security awareness among employees. Auditors also pay special attention to physical security and access control, which are sometimes neglected in companies focused primarily on IT.
How to maintain compliance and prepare for reassessment after three years?
Obtaining the TISAX label is not the end of the road, but rather the beginning. Certification is valid for three years, and maintaining compliance during this period requires ongoing work and commitment. Information security is a process, not a one-time project.
The key to maintaining compliance is the full implementation and regular operation of an Information Security Management System (ISMS). Implemented policies and procedures must not only be on paper, but actually applied in daily operations. All scheduled activities, such as:
-
Cyclical reviews of access privileges.
-
Regular vulnerability scanning and patch management.
-
Conducting a training and security awareness building program.
-
Regular testing of business continuity and incident response plans.
It is also essential to conduct regular internal audits, at least once a year. An internal audit, conducted by company staff or an external consultant, allows you to verify on an ongoing basis that the system is still operating effectively and identify any non-compliance before it becomes an issue during a recertification audit.
Preparations for reassessment (re-assessment) should begin well in advance, preferably about 6-9 months before the label expires. The process looks very similar to the first certification. A detailed self-assessment should be conducted again to verify the current state, identify any new gaps (which may have arisen as a result of changes in the company or the threat environment) and implement corrective actions. Then reselect the audit provider and go through the external evaluation process. Continuous maintenance and improvement of the SMS makes reassessment much simpler and less stressful than the first certification.
How can nFlo’s experience in ISO 27001 implementations help your company successfully prepare for an audit and achieve TISAX certification?
At nFlo, we have many years of hands-on experience in implementing and auditing Information Security Management Systems based on the international ISO/IEC 27001 standard. Since the TISAX standard is largely an extension of this very standard, our expertise and proven methodology provide the ideal foundation to effectively and efficiently prepare your company for the demanding TISAX audit.
Our support begins with a detailed Gap Analysis, during which we compare your current security status with the requirements of the VDA ISA catalog. Thanks to our experience with ISO 27001, we can quickly identify both common and TISAX-specific areas (such as prototype protection) that require special attention. Based on this analysis, we create a clear and realistic roadmap that guides your company step-by-step through the entire preparation process.
We help create and customize the necessary documentation - from Security Policies to risk and incident management procedures to detailed instructions. Our support is not limited to paper. We advise on the selection and configuration of appropriate technical measures, such as access control systems, encryption or security monitoring, which are necessary to meet VDA ISA requirements.
Crucially, we help with the practical implementation of processes and awareness building within the organization. We provide dedicated training for employees and management, and help you conduct a thorough self-assessment, which is the basis for an external audit. When you work with nFlo, you get a partner who not only “knows” the requirements, but can pragmatically translate them into the realities of your organization, maximizing the chances of passing the audit and obtaining the crucial TISAX label for your business.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
Learn More
Explore related articles in our knowledge base:
- Automotive cybersecurity: How to protect modern, connected vehicles?
- Cyber insurance for industry: What does your policy really cover and how to avoid costly surprises?
- How to implement NIS2 and not go crazy? Use regulation as leverage to get a budget for OT security
- IT thinks in terms of data, OT in terms of physics: Why don’t your security teams get along?
- Key Requirements of ISO 27001: The Road to a Certified Information Security Management System
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Related topics
See also:
