ISO Consulting Services

TISAX Trusted Information Security Assessment Exchange

TISAX labelling for automotive suppliers handling sensitive information.

TISAX — Trusted Information Security Assessment Exchange

TISAX® stands for Trusted Information Security Assessment Exchange. TISAX® enables mutual acceptance of information security assessments in the automotive industry and provides a common assessment and exchange mechanism that ensures the secure sharing of sensitive information to partner companies, to inspire trust throughout the automotive supply chain.

TISAX® was established by VDA (the German association of the automotive industry) and is operated by ENX Association, who have assessed and confirmed approved audit providers to perform the assessments.

Developed by automotive industry security experts and based on international information security management system (ISMS) standards like ISO/IEC 27001, TISAX® provides a catalogue of requirements, covering virtual, physical and social aspects of information security, specific to the automotive supply chain. This catalogue is referred to as the Information Security Assessment (ISA) and forms the basis of the assessment conducted by approved TISAX® audit providers.

What you get

  • TISAX scope definition
  • Information security implementation
  • Assessment preparation
  • Label maintenance support

Our 6-step methodology

  1. 01

    Gap analysis & scoping

  2. 02

    Risk assessment & treatment

  3. 03

    Documentation framework

  4. 04

    Implementation & training

  5. 05

    Internal audit & review

  6. 06

    Certification & sustenance

Automotive Information Security

What is TISAX®?

Trusted Information Security Assessment Exchange (TISAX®) is the automotive industry's globally recognised information security assessment and exchange mechanism.

Developed by the German Association of the Automotive Industry (VDA) and governed by the ENX Association, TISAX enables organisations to demonstrate that their Information Security Management System (ISMS) meets the strict security expectations of automotive manufacturers and suppliers.

Unlike ISO 27001 certification, TISAX is specifically tailored for the automotive sector. Assessments are performed using the VDA ISA (Information Security Assessment) catalogue, which incorporates industry-specific controls for information security, prototype protection, data protection and secure collaboration across the automotive supply chain.

Organisations successfully completing a TISAX assessment receive a TISAX label that can be securely shared with customers and business partners through the ENX platform, reducing duplicate customer audits and strengthening trust throughout the supply chain.

Overview

KEY FACTS

Assessment Standard

Based on the VDA ISA 6.0 catalogue and recognised by the ENX Association for the automotive industry.

Industry Recognition

Accepted by major automotive manufacturers and Tier-1 suppliers worldwide.

Business Benefit

Eliminates multiple customer security audits through a single recognised assessment process.

Security Focus

Covers information security, prototype protection, privacy requirements and secure collaboration across the automotive supply chain.

VDA ISA 6.0

TISAX 6.0 — The 10 Assessment Objectives

TISAX assessments are performed using the VDA ISA 6.0 catalogue. Depending on your organisation's business activities, one or more assessment objectives become applicable. Each objective evaluates specific security requirements across information security, prototype protection and data protection.

Objectives 1 – 5

Information Security

Confidential

High protection needs — AL 2

Strictly Confidential

Very high protection — AL 3

High Availability

Production-relevant suppliers — AL 2

Very High Availability

JIT / JIS critical suppliers — AL 3

Objectives 6 – 8

Prototype Protection

Data

Processing personal data (Art. 28 GDPR).

Special Data

Special categories (Art. 9 GDPR).

Objectives 9 – 10

Data Protection & Connected Services

Proto Parts

Prototype parts & components.

Proto Vehicles

Complete prototype vehicles

Test Vehicles

Camouflaged road / proving-ground use

Proto Events

Events, film & photo shoots

TISAX Assessment Levels

Same requirements — the level defines audit depth, not difficulty

AL 1

Self-Assessment

Completion of the VDA ISA self-assessment without external verification.

No recognised TISAX label — internal use only.

AL 2

Remote Assessment

Plausibility check by an ENX-approved audit provider — document review, evidence sampling and video interviews.

For HIGH protection needs — e.g., "Confidential", "High Availability".

AL 3

On-Site Assessment

Comprehensive on-site audit — direct system verification, interviews, facility inspection and validation of implemented security controls.

For VERY HIGH protection needs — "Strictly Confidential", prototype protection and critical automotive information.

What Changed with VDA ISA 6.0

In force for all new assessments since 1 April 2024

New Label Structure

'Info High' and 'Info Very High' replaced by four labels — Confidential, Strictly Confidential, High Availability, Very High Availability — separating confidentiality from availability.

IT + OT in Scope

Sharper focus on Operational Technology: production networks, controllers and shop-floor systems now sit squarely inside the assessment.

ISO/IEC 27001:2022 Alignment

Catalogue references updated to the 2022 revision of ISO 27001, plus mapping to NIST CSF — one ISMS serves multiple frameworks.

Maturity-Based Assessment

Each control area is rated on maturity levels 0–5; a consistent Level 3 ('Established') is required across all applicable controls.

Revised Data Protection Module

The catalogue for 'Data' and 'Special Data' objectives was fully rewritten around Art. 28 GDPR processor obligations.

English Master Version

English became the leading catalogue language, with translations issued from the English master.

Hawksberg Recommendation

Prepare Early for VDA ISA 6.0 Requirements

Organisations currently preparing for TISAX should align their Information Security Management System with the latest VDA ISA 6.0 requirements, strengthen supplier security governance, enhance operational technology protection and establish continuous compliance monitoring to ensure successful assessments and long-term customer confidence.

Our TISAX Services

End-to-end support from scoping to label

01

Scoping & ENX Registration Support

Define assessment scope, locations, objectives and assessment level; guide portal registration.

02

Gap Assessment (VDA ISA 6.0)

Department-wise maturity evaluation against all applicable controls, with a prioritised remediation roadmap.

03

ISMS Design & Documentation

Policies, procedures, risk assessments, SoA and evidence packs — audit-ready and tailored to your operations.

04

Control Implementation Support

Identity & access, endpoint, network segmentation, patching, incident response, supplier and prototype controls.

05

Training & Awareness

Management briefings, employee awareness and internal auditor training for sustained compliance.

06

Assessment Readiness & Audit Support

Self-assessment, mock audits, evidence review and support through the AL 2 / AL 3 assessment to label issuance.

Your TISAX Journey with Hawksberg

A proven six-step path to your TISAX label

Scope &
Register

Gap
Assessment

Build ISMS &
Remediate

Self-
Assessment

External Audit
(AL 2 / AL 3)

Label &
Maintain

Typical timeline: 4–9 months from kick-off to label, depending on scope, current maturity and assessment level. Our gap-first approach ensures no surprises at the external assessment.

Get in touch

Are you ready to apply?

Fill in the enquiry form below and our specialist will call you back.