Skip to content

TISAX® – Standards for the Automotive Industry

TISAX® (Trusted Information Security Assessment Exchange) is an industry-specific standard developed for the automotive sector to secure the confidential exchange of development, design, and production data across complex supply chains. The standard is based on ISO 27001 but extends it with automotive-specific requirements such as prototype protection and special data classifications.

TISAX was developed by the German Association of the Automotive Industry (VDA) and the ENX Association. With the release of ISA 6.0 in October 2023, the requirements were fundamentally updated and made mandatory as of April 1, 2024.


The increasing digitalization and interconnectivity of the automotive industry generate massive amounts of sensitive data. OEMs and suppliers continuously exchange development plans, source code, prototype data, and personal information. Without clear and uniform security requirements, each organization would need to conduct its own audits.

TISAX establishes a common standard by:

  • Reducing audit overhead across the supply chain
  • Enabling transparent proof of security levels
  • Creating competitive advantages through recognized certification
  • Harmonizing security requirements industry-wide

Pro Tip: Companies with a TISAX label signal a high level of information security to their partners – often a prerequisite for contracts in the automotive industry.


  1. Registration

    • Online registration via the ENX portal
    • Definition of scope
    • Fee-based registration required
  2. Assessment

    • Self-assessment: Using the ISA catalog
    • External audit: By accredited providers
    • Level selection: Depending on protection needs (AL 1–3)
  3. Exchange

    • TISAX report created after successful audit
    • Controlled sharing with selected partners
    • Validity: 3 years (re-assessment required afterward)

Assessment LevelDescriptionTypical Use
AL 1Self-assessment without external verificationInternal confirmation, rarely used
AL 2Plausibility check incl. document review and remote interviewsBasic IS, normal protection needs
AL 2.5Full remote audit, transitional step toward AL 3Flexible entry with upgrade option
AL 3Full on-site audit with complete verificationHighest protection (prototypes, PII)

ISA 6.0 – Current Version (mandatory from April 2024)

Section titled “ISA 6.0 – Current Version (mandatory from April 2024)”

Key updates include:

  • Stronger focus on IT/OT availability and business continuity
  • Revised and expanded privacy controls
  • New incident management requirements
  • English as the lead language
  • Mapping to ISO/IEC 27001:2022, NIST CSF 1.1
  • New controls for backup/restore, service continuity, secure client management

Note: Existing assessments remain valid. New audits from April 1, 2024, must follow ISA 6.0.


AspectISO 27001TISAX®
ScopeIndustry-neutral, globalAutomotive-specific
GovernanceISO-managed, long update cyclesENX-managed, faster updates possible
Audit approachSingle certification processMultiple levels (AL 1–3)
Special controlsGenericPrototype/test vehicle controls
Certificate validity3 years + annual surveillance3 years, no interim audits

Pro Tip: An existing ISO 27001 ISMS provides a solid foundation and significantly reduces TISAX effort.


  1. Define scope (business areas, sites, data types, customer demands).
  2. Conduct a gap analysis using ISA as checklist.
  3. Choose an audit provider (e.g., TÜV, DEKRA, SGS, Bureau Veritas, PwC, KPMG).
  • Secure management commitment
  • Allocate time, budget, staff
  • Perform internal audits as rehearsal
  • Structure documentation for evidence
  • Obtain and share the TISAX label
  • Address nonconformities systematically
  • Document lessons learned
  • Continuously review and update risks and controls

The fuentis Suite supports the TISAX process with:

  • Risk management module (ISA-aligned risk matrices, reporting)
  • Compliance module (ISA 6.0 templates, maturity scoring, gap analysis)
  • Asset management (inventory, classification, accountability)
  • Document management (central repository, versioning, workflows, audit trail)
  • Audit modules (planning, checklists, findings, effectiveness checks)

Pro Tip: Centralizing TISAX processes in one tool reduces administrative workload and increases transparency.


Pitfalls:

  1. Underestimating preparation effort (6–12 months for AL 3)
  2. Missing documentation
  3. Scope defined too broadly
  4. Overlooking prototype protection
  5. No internal test audits

Success factors:

  • Early planning (min. 6 months ahead)
  • Dedicated TISAX project lead
  • Pragmatic approach (focus on essentials)
  • Learn from TISAX-certified peers
  • Use tool support (e.g., fuentis Suite)
  1. Industry standard: TISAX is the de facto standard for IS in the automotive supply chain.
  2. Structured process: Registration, assessment, and exchange with AL 1–3 flexibility.
  3. ISA 6.0: Mandatory since April 2024, with strong focus on availability, incident management, and privacy.
  4. ISO 27001 synergy: Existing ISMS greatly eases TISAX implementation.
  5. Competitive edge: A TISAX label often secures market access and partner trust.