TISAX Compliance Software | Information Security Assessment Automation | Certivo - Certivo
TISAX (Trusted Information Security Assessment Exchange) Compliance
Your OEM Just Required TISAX AL3. Can You Prove Information Security Across Every Supplier Site?
TISAX compliance demands maturity level 3 across every VDA ISA control—with evidence from every supplier handling confidential data. VDA ISA 6.0 now splits labels into Confidentiality and Availability. Most OEMs require on-site AL3 assessments. Audit-ready evidence across your supply chain is mandatory.
Certivo automates supplier security evidence collection from declaration to audit-ready documentation.
17,500+
Sites assessed across 90+ countries
3 years
TISAX label validity period before reassessment
Level 3
Minimum maturity required across all VDA ISA controls
Regulation Overview
Jurisdiction
Global (originated in Germany; required across the global automotive supply chain)
Regulatory Body
ENX Association (on behalf of the German Association of the Automotive Industry / VDA)
Regulation Number
VDA ISA 6.0 (effective April 1, 2024)
Effective Date
TISAX launched 2017; ISA 6.0 mandatory for all new assessments from April 1, 2024
Official Source
ENX Portal
Key Threshold
Maturity Level 3 minimum across all applicable VDA ISA control questions
What is TISAX?
TISAX is the automotive industry's standardized information security assessment and exchange mechanism and the cornerstone of OEM supplier qualification requirements. For supply chain teams, the primary obligation is demonstrating information security maturity across confidentiality, availability, prototype protection, and data privacy—validated through an ENX-approved audit provider.
Over 17,500 sites across 90+ countries hold active TISAX labels as of 2025. VDA ISA 6.0, effective April 2024, replaced the previous label structure with four distinct labels: Confidential, Strictly Confidential, High Availability, and Very High Availability. OEMs including Volkswagen, BMW, Stellantis, and PACCAR now mandate TISAX as a prerequisite for RFQ participation and ongoing supply chain engagement.
TISAX compliance requires documented evidence of a functioning ISMS—policies, risk assessments, access controls, and incident response—from every supplier site handling OEM data. When VDA updates the ISA catalog, your entire security management system requires reassessment against the new controls.
Key Components / Sub-Frameworks
Obligation
Defines all control questions and maturity targets for assessment
VDA ISA Catalog
Information Security Assessment questionnaire (currently v6.0)
Obligation
OEM requirement determines level; most require AL3 for confidential data
Assessment Levels (AL1–AL3)
Tiered audit depth from self-assessment to on-site inspection
Obligation
Protects trade secrets, design data, and proprietary specifications
Confidentiality Labels
Confidential / Strictly Confidential (replaced Info High / Very High)
Obligation
Ensures supplier IT/OT resilience against ransomware and disruption
Availability Labels
High Availability / Very High Availability
Obligation
Required for suppliers handling prototypes, test vehicles, or design data
Prototype Protection
Physical and organizational safeguards for pre-production components
Obligation
Mandatory for suppliers processing personal data on behalf of OEMs
Data Protection
Personal data handling requirements beyond GDPR baseline
Key Compliance Requirements
Who Must Comply
- Tier 1, Tier 2, and Tier 3 suppliers handling confidential OEM information
- Service providers processing automotive design, engineering, or production data
- IT and software vendors integrated into automotive development environments
- Logistics providers transporting prototypes or sensitive components
- Non-European companies supplying into European OEM supply chains
- Contract manufacturers and assembly partners with OEM data access
Key Thresholds
Maturity Level 3
Minimum score required per VDA ISA control question for label issuance
AL3 (Assessment Level 3)
On-site audit required for very high protection needs—most OEM standard
3 years
TISAX label validity period before mandatory reassessment
6–12 months
Typical implementation timeline for organizations without existing ISMS
Core Obligations
- ISMS Implementation
Establish and maintain an Information Security Management System per VDA ISA
DEADLINE
Before assessment registration - VDA ISA Self-Assessment
Complete the full ISA questionnaire and document maturity levels per control
DEADLINE
Before engaging audit provider - ENX Portal Registration
Register as TISAX participant, define scopes, locations, and assessment objectives
DEADLINE
Before ordering assessment - External Assessment
Undergo AL2 (remote) or AL3 (on-site) audit by ENX-approved audit provider
DEADLINE
Per OEM contractual timelines - Supply Chain Flowdown
Ensure sub-tier suppliers meet comparable information security standards
DEADLINE
Ongoing
TISAX-Specific Pain Points
The Multi-Site Evidence Scramble
Your OEM requires AL3 across four manufacturing sites and two engineering centers. Each site needs its own VDA ISA self-assessment, but ISMS documentation lives in different systems, different languages, and different formats.
The Maturity Level Gap
The auditor scores your incident response process at maturity level 2—documented but not consistently practiced.
The Sub-Tier Visibility Problem
TISAX requires you to assess and manage information security risks from your own suppliers.
The ISA 6.0 Transition Burden
VDA ISA 6.0 split the Information Security label into four separate objectives. Six new control questions target ransomware defense and business continuity.
Certivo in Action
Certivo Workflow
GET EVIDENCE IN
Collect Security Evidence from Every Supplier—Without the Chasing
CORA launches targeted campaigns to collect ISMS documentation, security questionnaire responses, and TISAX label status from your entire supplier base, follows up automatically, and accepts responses in any format.
- Launch information security campaigns to hundreds of suppliers with one click
- CORA-powered outreach in suppliers' native languages
- Accept any format: PDFs, Excel questionnaires, ISO 27001 certificates, TISAX label screenshots
- Track response rates and escalate non-responders automatically
MAKE SENSE OF IT
Know Instantly Where Supplier Security Gaps Exist Across Your Network
CORA parses every supplier submission, extracts security control evidence, validates against VDA ISA 6.0 requirements, and flags maturity gaps automatically.
- Automatic validation against all VDA ISA 6.0 control questions
- Real-time alerts when supplier TISAX labels approach expiration
PROVE COMPLIANCE OUT
Respond to OEM Audit Requests in Hours, Not Weeks
Generate audit-ready documentation packages and supplier security evidence summaries instantly from validated data.
Related Regulations
- ISO 27001
TISAX builds on ISO 27001 with automotive-specific additions; ~70% control overlap - IATF 16949
IATF requires consideration of information security and contingency planning - NIS 2 Directive
EU cybersecurity directive; ENX confirms TISAX meets all relevant NIS 2 requirements - EU GDPR
TISAX data protection module addresses personal data handling beyond GDPR baseline - EU Cyber Resilience Act
CRA requires cybersecurity for products with digital elements; TISAX addresses supply chain security - UNECE WP.29 / R155
UN vehicle cybersecurity regulation requiring CSMS across the supply chain
Industries Most Impacted
Return on Investment
80%
Reduction in Evidence Collection Labor
4 Hours
To OEM Audit Package
Continuous
TISAX Label Monitoring
Key Statistics
17,500+
TISAX-assessed sites tracked with automatic label monitoring
99.2%
Evidence extraction accuracy from supplier security declarations
95%
Supplier response rate with CORA-powered campaigns
Frequently Asked Questions
What companies are subject to TISAX requirements?
Any organization handling confidential information from automotive OEMs—including Tier 1 through Tier 3 suppliers, engineering service providers, IT vendors, and logistics companies transporting prototypes—can be required to hold a TISAX label.
What are the consequences of failing a TISAX assessment?
While TISAX is not a legal regulation, failing to achieve the required label effectively blocks business with OEMs that mandate it.
How does VDA ISA 6.0 differ from previous versions?
ISA 6.0, effective April 2024, replaced the "Info High" and "Info Very High" labels with four distinct labels—Confidential, Strictly Confidential, High Availability, and Very High Availability.
What assessment formats does Certivo accept from suppliers?
Certivo accepts any format through its specialized substance reporting solutions approach: PDF certificates, Excel security questionnaires, ISO 27001 audit reports, TISAX label confirmations, XML exports, and freeform responses.
Does Certivo support TISAX alongside ISO 27001 and other security frameworks?
Yes. Certivo validates supplier security evidence against TISAX VDA ISA 6.0, ISO 27001, NIS 2, and CRA requirements simultaneously.