Updated: 5 July 2026
What is TISAX and who does it apply to? TISAX (Trusted Information Security Assessment Exchange) is an information security standard created by VDA (Verband der Automobilindustrie) for the automotive sector and its supply chain. Based on VDA ISA (Information Security Assessment), TISAX defines information protection requirements across the automotive supply chain – from vehicle designs and technical data to personal data and prototype protection.
If your organisation provides IT, engineering, legal, or manufacturing services to an OEM (Volkswagen, BMW, Mercedes-Benz, Stellantis) or a Tier 1 supplier, you will almost certainly be required to achieve TISAX. Certification is managed by ENX Association and results are not published publicly – they are shared exclusively between trusted network participants.
TISAX certification – at a glance:
- TISAX assesses six modules: information security, personal data protection, prototype protection, connected vehicles, manufacturing services, and supplier compliance – not every module applies to every organisation
- The Assessment Level (AL) determines audit depth: AL1 is self-assessment, AL2 is an audit by an ENX-accredited external auditor, AL3 is the deepest level for organisations protecting highly sensitive data or prototypes
- TISAX results are exchanged within the ENX network and are valid for 3 years – after 3 years a re-assessment is required
- Preparing for TISAX AL2 for an organisation of 50 to 200 employees typically takes 6 to 12 months
- VDA ISA 6.0 (applicable from 2024) introduced new requirements for cybersecurity and software supply chain security
- Patronusec guides organisations through the complete TISAX preparation cycle – from gap analysis to support during the ENX audit
Table of Contents
What are the TISAX modules and which one applies to your organisation?
TISAX is divided into thematic modules – not every organisation must satisfy all of them. The client (OEM or Tier 1) specifies which modules are required as part of the business relationship.
TISAX modules (VDA ISA 6.0):
| Module | Scope | Typically required by |
|---|---|---|
| IS (Information Security) | Protection of confidential business information | All suppliers with access to OEM data |
| PD (Data Protection) | Protection of personal data | Organisations processing OEM employee or customer data |
| HS (Prototype Protection) | Protection of prototypes and pre-production vehicles | Organisations photographing, transporting, or storing prototypes |
| SW (Automotive Software) | Vehicle software security | ECU suppliers, embedded software, OTA providers |
| CS (Connected Vehicles) | Cybersecurity for connected vehicles | Telematics, V2X, fleet backend suppliers |
| SC (Suppliers Compliance) | Subcontractor security management | Organisations with complex supplier chains |
How OEMs communicate required modules:
In the contract or supplier management system (for example, Volkswagen Supplier Portal, BMWgroup.com), the OEM specifies the required module and Assessment Level. The most common requirement for IT and professional services suppliers: IS plus PD, Assessment Level AL2.
Patronusec Insight: Organisations new to automotive supply often confuse TISAX with ISO 27001 – assuming that holding ISO 27001 makes TISAX a formality. In practice, VDA ISA 6.0 contains dozens of automotive-specific controls without direct equivalents in ISO 27001 – particularly in the areas of prototype protection and subcontractor management. The gap analysis between ISO 27001 and VDA ISA typically takes us 2 to 3 weeks and identifies precisely what needs to be added. We deliver these projects as part of our TISAX service.
What distinguishes Assessment Levels AL1, AL2, and AL3 in TISAX?
The Assessment Level determines the depth of the security evaluation – it governs audit methods and the required auditor profile.
AL1 – Self-assessment:
The organisation completes the VDA ISA questionnaire independently and declares the result. No external auditor is required. Used for organisations with access to low-sensitivity information. AL1 results are exchanged within the ENX network but carry less weight than AL2 or AL3.
AL2 – External audit (the standard for most suppliers):
The audit is conducted by an external TISAX auditor accredited by ENX. It includes a documentation review, interviews, and an on-site inspection. Results are valid for 3 years. This is the requirement for most IT and engineering suppliers to OEMs.
AL3 – Extended audit (for highly sensitive data):
A more intensive audit with extended technical testing, a greater number of interviews, and an on-site inspection at every location in scope. Required for organisations protecting trade secrets at the highest classification level or handling prototypes.
Comparison of Assessment Levels:
| Feature | AL1 | AL2 | AL3 |
|---|---|---|---|
| Method | Self-assessment | External audit | Extended audit |
| Auditor | None | ENX-accredited | ENX-accredited |
| Preparation time | 2 to 4 months | 6 to 12 months | 12 to 18 months |
| Indicative cost | £4,000 to £12,000 | £40,000 to £120,000 | £80,000 to £250,000 |
| Validity | 3 years | 3 years | 3 years |
Received a TISAX AL2 requirement from an automotive client and not sure where to begin?
Patronusec conducts a TISAX gap analysis – an assessment of your current security posture against VDA ISA 6.0 requirements. Within 3 to 4 weeks, we deliver a report listing gaps, priorities, and a realistic project timeline.
How does a TISAX audit work and who can conduct it?
A TISAX audit is conducted by an Audit Provider accredited by ENX Association. The list of accredited providers is available on the ENX portal.
The TISAX AL2 audit process:
- ENX portal registration – the organisation creates an account on the ENX Portal and declares the assessment scope (modules and locations)
- Select an Audit Provider – the organisation selects an accredited provider from the ENX list
- Kick-off and gap analysis – the auditor conducts an initial assessment (optional but recommended)
- On-site assessment – the auditor visits each location in scope, conducts interviews and inspection
- Report – the auditor issues a results report in the ENX portal
- Result sharing – following a positive result, the OEM or client can view results in the ENX portal (once the organisation grants sharing consent)
What the auditor examines during inspection:
- Physical access controls to IT premises
- Mobile device and removable media management
- Network security and segmentation
- Incident management and response planning
- Employee security awareness
- Subcontractor management (if they have access to OEM data)
Patronusec Insight: The most common surprise during a TISAX AL2 audit is the requirement for physical inspection – the auditor asks about card access controls, CCTV coverage, media destruction procedures, and visitor management. IT organisations often have strong technical controls but neglect physical ones. The second common trap is BYOD (Bring Your Own Device) management – VDA ISA 6.0 specifies in detail what must be configured on personal devices that have access to OEM data. We cover these requirements in detail during our TISAX preparation workshops. Details available in our TISAX offer.
How do you prepare your organisation for TISAX certification step by step?
Step 1: Define scope (modules and locations)
Confirm with the OEM client which modules are required and for which locations. The TISAX scope must be defined in the ENX Portal before the audit begins.
Step 2: Gap analysis against VDA ISA 6.0
Conduct or commission a gap analysis between your current security posture and VDA ISA requirements. If you hold ISO 27001, the gap analysis will show what ISO 27001 covers and what additional controls are needed for TISAX.
Step 3: Remediation project
Based on the gap analysis, build a plan to close identified gaps – both documentation gaps (policies, procedures) and technical gaps (access controls, encryption, MDM, monitoring).
Step 4: Training and awareness
VDA ISA requires that employees with access to OEM data receive security awareness training. Documentation of training must be available to the auditor.
Step 5: ENX registration and Audit Provider selection
Register the organisation on the ENX Portal and select an accredited Audit Provider. Some providers offer a pre-assessment before the formal audit.
Step 6: Audit and result sharing
Following a positive audit, results are available in the ENX Portal and can be shared with the automotive client.
FAQ – TISAX certification
Does ISO 27001 exempt an organisation from TISAX?
No – ISO 27001 and TISAX are separate standards. ISO 27001 is a helpful foundation (many controls overlap), but VDA ISA 6.0 contains automotive-specific requirements not present in ISO 27001. A gap analysis between ISO 27001 and VDA ISA typically identifies 30 to 50% of requirements that need to be added.
How long are TISAX results valid?
Three years from the date of the assessment. After 3 years, a full re-assessment is required. Unlike ISO 27001, there are no mandatory annual surveillance audits between assessments.
Does TISAX apply to all employees?
The TISAX scope applies to employees and systems with access to OEM data. If not all employees have access to such data, the scope may be limited to a specific department or project. Scope must be precisely defined before the audit.
How much does TISAX certification cost?
Cost depends on the Assessment Level, number of locations, and selected modules. AL2 for one location (IS plus PD modules): the Audit Provider typically charges £12,000 to £35,000. Add the preparation cost (gap analysis, remediation, consultant) – typically a similar amount. Patronusec provides a project quotation after the gap analysis.
Is TISAX only required for direct OEM suppliers?
No – TISAX requirements flow down the supply chain. If a Tier 1 supplier (direct OEM supplier) requires its subcontractors to protect OEM data, it may require TISAX from them. IT firms, legal advisers, and consultants serving Tier 1 suppliers are increasingly required to hold TISAX even without a direct OEM contract.
How does Patronusec help with TISAX preparation?
We conduct VDA ISA 6.0 gap analyses, run the remediation project, and prepare the documentation required by the auditor. We work with the client during Audit Provider selection and remain available for consultation during the formal audit. For organisations that already hold ISO 27001, the TISAX preparation project is considerably shorter – we focus on the automotive-specific requirements.
TISAX certification – free consultation
Patronusec supports automotive suppliers preparing for TISAX certification – from the initial gap analysis to support during the ENX audit. We work with IT, engineering, and professional services firms entering or already operating in the automotive supply chain.
In a free 30-minute consultation we will help you:
- Determine which modules and Assessment Level your automotive client requires
- Assess how many VDA ISA 6.0 requirements your organisation already satisfies (particularly if you hold ISO 27001)
- Plan the timeline and budget for the TISAX preparation project
- Choose an Audit Provider and understand what the auditor looks for during inspection
Free consultation | TISAX certification | ISO 27001 | vCISO | Penetration testing