Cybersecurity

Blog space

TISAX Certification – How It Works and What an Automotive Supplier Must Do

Inside this article:

  • Which TISAX modules may apply to automotive suppliers
  • How AL1, AL2 and AL3 differ
  • What preparation for a TISAX audit looks like
TISAX certification

Updated: 5 July 2026

What is TISAX and who does it apply to? TISAX (Trusted Information Security Assessment Exchange) is an information security standard created by VDA (Verband der Automobilindustrie) for the automotive sector and its supply chain. Based on VDA ISA (Information Security Assessment), TISAX defines information protection requirements across the automotive supply chain – from vehicle designs and technical data to personal data and prototype protection.

If your organisation provides IT, engineering, legal, or manufacturing services to an OEM (Volkswagen, BMW, Mercedes-Benz, Stellantis) or a Tier 1 supplier, you will almost certainly be required to achieve TISAX. Certification is managed by ENX Association and results are not published publicly – they are shared exclusively between trusted network participants.

TISAX certification – at a glance:

  1. TISAX assesses six modules: information security, personal data protection, prototype protection, connected vehicles, manufacturing services, and supplier compliance – not every module applies to every organisation
  2. The Assessment Level (AL) determines audit depth: AL1 is self-assessment, AL2 is an audit by an ENX-accredited external auditor, AL3 is the deepest level for organisations protecting highly sensitive data or prototypes
  3. TISAX results are exchanged within the ENX network and are valid for 3 years – after 3 years a re-assessment is required
  4. Preparing for TISAX AL2 for an organisation of 50 to 200 employees typically takes 6 to 12 months
  5. VDA ISA 6.0 (applicable from 2024) introduced new requirements for cybersecurity and software supply chain security
  6. Patronusec guides organisations through the complete TISAX preparation cycle – from gap analysis to support during the ENX audit


What are the TISAX modules and which one applies to your organisation?

TISAX is divided into thematic modules – not every organisation must satisfy all of them. The client (OEM or Tier 1) specifies which modules are required as part of the business relationship.

TISAX modules (VDA ISA 6.0):

ModuleScopeTypically required by
IS (Information Security)Protection of confidential business informationAll suppliers with access to OEM data
PD (Data Protection)Protection of personal dataOrganisations processing OEM employee or customer data
HS (Prototype Protection)Protection of prototypes and pre-production vehiclesOrganisations photographing, transporting, or storing prototypes
SW (Automotive Software)Vehicle software securityECU suppliers, embedded software, OTA providers
CS (Connected Vehicles)Cybersecurity for connected vehiclesTelematics, V2X, fleet backend suppliers
SC (Suppliers Compliance)Subcontractor security managementOrganisations with complex supplier chains

How OEMs communicate required modules:

In the contract or supplier management system (for example, Volkswagen Supplier Portal, BMWgroup.com), the OEM specifies the required module and Assessment Level. The most common requirement for IT and professional services suppliers: IS plus PD, Assessment Level AL2.

Patronusec Insight: Organisations new to automotive supply often confuse TISAX with ISO 27001 – assuming that holding ISO 27001 makes TISAX a formality. In practice, VDA ISA 6.0 contains dozens of automotive-specific controls without direct equivalents in ISO 27001 – particularly in the areas of prototype protection and subcontractor management. The gap analysis between ISO 27001 and VDA ISA typically takes us 2 to 3 weeks and identifies precisely what needs to be added. We deliver these projects as part of our TISAX service.

What distinguishes Assessment Levels AL1, AL2, and AL3 in TISAX?

The Assessment Level determines the depth of the security evaluation – it governs audit methods and the required auditor profile.

AL1 – Self-assessment:

The organisation completes the VDA ISA questionnaire independently and declares the result. No external auditor is required. Used for organisations with access to low-sensitivity information. AL1 results are exchanged within the ENX network but carry less weight than AL2 or AL3.

AL2 – External audit (the standard for most suppliers):

The audit is conducted by an external TISAX auditor accredited by ENX. It includes a documentation review, interviews, and an on-site inspection. Results are valid for 3 years. This is the requirement for most IT and engineering suppliers to OEMs.

AL3 – Extended audit (for highly sensitive data):

A more intensive audit with extended technical testing, a greater number of interviews, and an on-site inspection at every location in scope. Required for organisations protecting trade secrets at the highest classification level or handling prototypes.

Comparison of Assessment Levels:

FeatureAL1AL2AL3
MethodSelf-assessmentExternal auditExtended audit
AuditorNoneENX-accreditedENX-accredited
Preparation time2 to 4 months6 to 12 months12 to 18 months
Indicative cost£4,000 to £12,000£40,000 to £120,000£80,000 to £250,000
Validity3 years3 years3 years

Received a TISAX AL2 requirement from an automotive client and not sure where to begin?

Patronusec conducts a TISAX gap analysis – an assessment of your current security posture against VDA ISA 6.0 requirements. Within 3 to 4 weeks, we deliver a report listing gaps, priorities, and a realistic project timeline.

Book a TISAX gap analysis


How does a TISAX audit work and who can conduct it?

A TISAX audit is conducted by an Audit Provider accredited by ENX Association. The list of accredited providers is available on the ENX portal.

The TISAX AL2 audit process:

  1. ENX portal registration – the organisation creates an account on the ENX Portal and declares the assessment scope (modules and locations)
  2. Select an Audit Provider – the organisation selects an accredited provider from the ENX list
  3. Kick-off and gap analysis – the auditor conducts an initial assessment (optional but recommended)
  4. On-site assessment – the auditor visits each location in scope, conducts interviews and inspection
  5. Report – the auditor issues a results report in the ENX portal
  6. Result sharing – following a positive result, the OEM or client can view results in the ENX portal (once the organisation grants sharing consent)

What the auditor examines during inspection:

  • Physical access controls to IT premises
  • Mobile device and removable media management
  • Network security and segmentation
  • Incident management and response planning
  • Employee security awareness
  • Subcontractor management (if they have access to OEM data)

Patronusec Insight: The most common surprise during a TISAX AL2 audit is the requirement for physical inspection – the auditor asks about card access controls, CCTV coverage, media destruction procedures, and visitor management. IT organisations often have strong technical controls but neglect physical ones. The second common trap is BYOD (Bring Your Own Device) management – VDA ISA 6.0 specifies in detail what must be configured on personal devices that have access to OEM data. We cover these requirements in detail during our TISAX preparation workshops. Details available in our TISAX offer.

How do you prepare your organisation for TISAX certification step by step?

Step 1: Define scope (modules and locations)

Confirm with the OEM client which modules are required and for which locations. The TISAX scope must be defined in the ENX Portal before the audit begins.

Step 2: Gap analysis against VDA ISA 6.0

Conduct or commission a gap analysis between your current security posture and VDA ISA requirements. If you hold ISO 27001, the gap analysis will show what ISO 27001 covers and what additional controls are needed for TISAX.

Step 3: Remediation project

Based on the gap analysis, build a plan to close identified gaps – both documentation gaps (policies, procedures) and technical gaps (access controls, encryption, MDM, monitoring).

Step 4: Training and awareness

VDA ISA requires that employees with access to OEM data receive security awareness training. Documentation of training must be available to the auditor.

Step 5: ENX registration and Audit Provider selection

Register the organisation on the ENX Portal and select an accredited Audit Provider. Some providers offer a pre-assessment before the formal audit.

Step 6: Audit and result sharing

Following a positive audit, results are available in the ENX Portal and can be shared with the automotive client.

FAQ – TISAX certification

Does ISO 27001 exempt an organisation from TISAX?

No – ISO 27001 and TISAX are separate standards. ISO 27001 is a helpful foundation (many controls overlap), but VDA ISA 6.0 contains automotive-specific requirements not present in ISO 27001. A gap analysis between ISO 27001 and VDA ISA typically identifies 30 to 50% of requirements that need to be added.

How long are TISAX results valid?

Three years from the date of the assessment. After 3 years, a full re-assessment is required. Unlike ISO 27001, there are no mandatory annual surveillance audits between assessments.

Does TISAX apply to all employees?

The TISAX scope applies to employees and systems with access to OEM data. If not all employees have access to such data, the scope may be limited to a specific department or project. Scope must be precisely defined before the audit.

How much does TISAX certification cost?

Cost depends on the Assessment Level, number of locations, and selected modules. AL2 for one location (IS plus PD modules): the Audit Provider typically charges £12,000 to £35,000. Add the preparation cost (gap analysis, remediation, consultant) – typically a similar amount. Patronusec provides a project quotation after the gap analysis.

Is TISAX only required for direct OEM suppliers?

No – TISAX requirements flow down the supply chain. If a Tier 1 supplier (direct OEM supplier) requires its subcontractors to protect OEM data, it may require TISAX from them. IT firms, legal advisers, and consultants serving Tier 1 suppliers are increasingly required to hold TISAX even without a direct OEM contract.

How does Patronusec help with TISAX preparation?

We conduct VDA ISA 6.0 gap analyses, run the remediation project, and prepare the documentation required by the auditor. We work with the client during Audit Provider selection and remain available for consultation during the formal audit. For organisations that already hold ISO 27001, the TISAX preparation project is considerably shorter – we focus on the automotive-specific requirements.


TISAX certification – free consultation

Patronusec supports automotive suppliers preparing for TISAX certification – from the initial gap analysis to support during the ENX audit. We work with IT, engineering, and professional services firms entering or already operating in the automotive supply chain.

In a free 30-minute consultation we will help you:

  • Determine which modules and Assessment Level your automotive client requires
  • Assess how many VDA ISA 6.0 requirements your organisation already satisfies (particularly if you hold ISO 27001)
  • Plan the timeline and budget for the TISAX preparation project
  • Choose an Audit Provider and understand what the auditor looks for during inspection

Free consultation | TISAX certification | ISO 27001 | vCISO | Penetration testing

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top