TISAX® – Standards for the Automotive Industry
TISAX® (Trusted Information Security Assessment Exchange) is an industry-specific standard developed for the automotive sector to secure the confidential exchange of development, design, and production data across complex supply chains. The standard is based on ISO 27001 but extends it with automotive-specific requirements such as prototype protection and special data classifications.
TISAX was developed by the German Association of the Automotive Industry (VDA) and the ENX Association. With the release of ISA 6.0 in October 2023, the requirements were fundamentally updated and made mandatory as of April 1, 2024.
Why TISAX® Matters
Section titled “Why TISAX® Matters”The increasing digitalization and interconnectivity of the automotive industry generate massive amounts of sensitive data. OEMs and suppliers continuously exchange development plans, source code, prototype data, and personal information. Without clear and uniform security requirements, each organization would need to conduct its own audits.
TISAX establishes a common standard by:
- Reducing audit overhead across the supply chain
- Enabling transparent proof of security levels
- Creating competitive advantages through recognized certification
- Harmonizing security requirements industry-wide
Pro Tip: Companies with a TISAX label signal a high level of information security to their partners – often a prerequisite for contracts in the automotive industry.
Core Concepts and Requirements
Section titled “Core Concepts and Requirements”The TISAX® Process in Three Steps
Section titled “The TISAX® Process in Three Steps”-
Registration
- Online registration via the ENX portal
- Definition of scope
- Fee-based registration required
-
Assessment
- Self-assessment: Using the ISA catalog
- External audit: By accredited providers
- Level selection: Depending on protection needs (AL 1–3)
-
Exchange
- TISAX report created after successful audit
- Controlled sharing with selected partners
- Validity: 3 years (re-assessment required afterward)
Assessment Levels and Protection Needs
Section titled “Assessment Levels and Protection Needs”| Assessment Level | Description | Typical Use |
|---|---|---|
| AL 1 | Self-assessment without external verification | Internal confirmation, rarely used |
| AL 2 | Plausibility check incl. document review and remote interviews | Basic IS, normal protection needs |
| AL 2.5 | Full remote audit, transitional step toward AL 3 | Flexible entry with upgrade option |
| AL 3 | Full on-site audit with complete verification | Highest protection (prototypes, PII) |
ISA 6.0 – Current Version (mandatory from April 2024)
Section titled “ISA 6.0 – Current Version (mandatory from April 2024)”Key updates include:
- Stronger focus on IT/OT availability and business continuity
- Revised and expanded privacy controls
- New incident management requirements
- English as the lead language
- Mapping to ISO/IEC 27001:2022, NIST CSF 1.1
- New controls for backup/restore, service continuity, secure client management
Note: Existing assessments remain valid. New audits from April 1, 2024, must follow ISA 6.0.
TISAX® vs. ISO 27001
Section titled “TISAX® vs. ISO 27001”| Aspect | ISO 27001 | TISAX® |
|---|---|---|
| Scope | Industry-neutral, global | Automotive-specific |
| Governance | ISO-managed, long update cycles | ENX-managed, faster updates possible |
| Audit approach | Single certification process | Multiple levels (AL 1–3) |
| Special controls | Generic | Prototype/test vehicle controls |
| Certificate validity | 3 years + annual surveillance | 3 years, no interim audits |
Pro Tip: An existing ISO 27001 ISMS provides a solid foundation and significantly reduces TISAX effort.
Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Preparation
Section titled “Preparation”- Define scope (business areas, sites, data types, customer demands).
- Conduct a gap analysis using ISA as checklist.
- Choose an audit provider (e.g., TÜV, DEKRA, SGS, Bureau Veritas, PwC, KPMG).
During the Assessment
Section titled “During the Assessment”- Secure management commitment
- Allocate time, budget, staff
- Perform internal audits as rehearsal
- Structure documentation for evidence
After the Assessment
Section titled “After the Assessment”- Obtain and share the TISAX label
- Address nonconformities systematically
- Document lessons learned
- Continuously review and update risks and controls
Integration with the fuentis Suite
Section titled “Integration with the fuentis Suite”The fuentis Suite supports the TISAX process with:
- Risk management module (ISA-aligned risk matrices, reporting)
- Compliance module (ISA 6.0 templates, maturity scoring, gap analysis)
- Asset management (inventory, classification, accountability)
- Document management (central repository, versioning, workflows, audit trail)
- Audit modules (planning, checklists, findings, effectiveness checks)
Pro Tip: Centralizing TISAX processes in one tool reduces administrative workload and increases transparency.
Common Pitfalls and Success Factors
Section titled “Common Pitfalls and Success Factors”Pitfalls:
- Underestimating preparation effort (6–12 months for AL 3)
- Missing documentation
- Scope defined too broadly
- Overlooking prototype protection
- No internal test audits
Success factors:
- Early planning (min. 6 months ahead)
- Dedicated TISAX project lead
- Pragmatic approach (focus on essentials)
- Learn from TISAX-certified peers
- Use tool support (e.g., fuentis Suite)
Key Takeaways
Section titled “Key Takeaways”- Industry standard: TISAX is the de facto standard for IS in the automotive supply chain.
- Structured process: Registration, assessment, and exchange with AL 1–3 flexibility.
- ISA 6.0: Mandatory since April 2024, with strong focus on availability, incident management, and privacy.
- ISO 27001 synergy: Existing ISMS greatly eases TISAX implementation.
- Competitive edge: A TISAX label often secures market access and partner trust.