TISAX Compliance Software | Information Security Assessment Automation | Certivo - Certivo

TISAX (Trusted Information Security Assessment Exchange) Compliance

Your OEM Just Required TISAX AL3. Can You Prove Information Security Across Every Supplier Site?

TISAX compliance demands maturity level 3 across every VDA ISA control—with evidence from every supplier handling confidential data. VDA ISA 6.0 now splits labels into Confidentiality and Availability. Most OEMs require on-site AL3 assessments. Audit-ready evidence across your supply chain is mandatory.

Certivo automates supplier security evidence collection from declaration to audit-ready documentation.

17,500+

Sites assessed across 90+ countries

3 years

TISAX label validity period before reassessment

Level 3

Minimum maturity required across all VDA ISA controls

Regulation Overview

Jurisdiction
Global (originated in Germany; required across the global automotive supply chain)
Regulatory Body
ENX Association (on behalf of the German Association of the Automotive Industry / VDA)
Regulation Number
VDA ISA 6.0 (effective April 1, 2024)
Effective Date
TISAX launched 2017; ISA 6.0 mandatory for all new assessments from April 1, 2024
Official Source
ENX Portal
Key Threshold
Maturity Level 3 minimum across all applicable VDA ISA control questions

What is TISAX?

TISAX is the automotive industry's standardized information security assessment and exchange mechanism and the cornerstone of OEM supplier qualification requirements. For supply chain teams, the primary obligation is demonstrating information security maturity across confidentiality, availability, prototype protection, and data privacy—validated through an ENX-approved audit provider.

Over 17,500 sites across 90+ countries hold active TISAX labels as of 2025. VDA ISA 6.0, effective April 2024, replaced the previous label structure with four distinct labels: Confidential, Strictly Confidential, High Availability, and Very High Availability. OEMs including Volkswagen, BMW, Stellantis, and PACCAR now mandate TISAX as a prerequisite for RFQ participation and ongoing supply chain engagement.

TISAX compliance requires documented evidence of a functioning ISMS—policies, risk assessments, access controls, and incident response—from every supplier site handling OEM data. When VDA updates the ISA catalog, your entire security management system requires reassessment against the new controls.

Key Components / Sub-Frameworks

Obligation
Defines all control questions and maturity targets for assessment
VDA ISA Catalog
Information Security Assessment questionnaire (currently v6.0)
Obligation
OEM requirement determines level; most require AL3 for confidential data
Assessment Levels (AL1–AL3)
Tiered audit depth from self-assessment to on-site inspection
Obligation
Protects trade secrets, design data, and proprietary specifications
Confidentiality Labels
Confidential / Strictly Confidential (replaced Info High / Very High)
Obligation
Ensures supplier IT/OT resilience against ransomware and disruption
Availability Labels
High Availability / Very High Availability
Obligation
Required for suppliers handling prototypes, test vehicles, or design data
Prototype Protection
Physical and organizational safeguards for pre-production components
Obligation
Mandatory for suppliers processing personal data on behalf of OEMs
Data Protection
Personal data handling requirements beyond GDPR baseline

Key Compliance Requirements

Who Must Comply

Key Thresholds

Maturity Level 3
Minimum score required per VDA ISA control question for label issuance
AL3 (Assessment Level 3)
On-site audit required for very high protection needs—most OEM standard
3 years
TISAX label validity period before mandatory reassessment
6–12 months
Typical implementation timeline for organizations without existing ISMS

Core Obligations

  1. ISMS Implementation
    Establish and maintain an Information Security Management System per VDA ISA
    DEADLINE
    Before assessment registration
  2. VDA ISA Self-Assessment
    Complete the full ISA questionnaire and document maturity levels per control
    DEADLINE
    Before engaging audit provider
  3. ENX Portal Registration
    Register as TISAX participant, define scopes, locations, and assessment objectives
    DEADLINE
    Before ordering assessment
  4. External Assessment
    Undergo AL2 (remote) or AL3 (on-site) audit by ENX-approved audit provider
    DEADLINE
    Per OEM contractual timelines
  5. Supply Chain Flowdown
    Ensure sub-tier suppliers meet comparable information security standards
    DEADLINE
    Ongoing

TISAX-Specific Pain Points

The Multi-Site Evidence Scramble
Your OEM requires AL3 across four manufacturing sites and two engineering centers. Each site needs its own VDA ISA self-assessment, but ISMS documentation lives in different systems, different languages, and different formats.

The Maturity Level Gap
The auditor scores your incident response process at maturity level 2—documented but not consistently practiced.

The Sub-Tier Visibility Problem
TISAX requires you to assess and manage information security risks from your own suppliers.

The ISA 6.0 Transition Burden
VDA ISA 6.0 split the Information Security label into four separate objectives. Six new control questions target ransomware defense and business continuity.

Certivo in Action

Certivo Workflow

GET EVIDENCE IN
Collect Security Evidence from Every Supplier—Without the Chasing

CORA launches targeted campaigns to collect ISMS documentation, security questionnaire responses, and TISAX label status from your entire supplier base, follows up automatically, and accepts responses in any format.

MAKE SENSE OF IT
Know Instantly Where Supplier Security Gaps Exist Across Your Network

CORA parses every supplier submission, extracts security control evidence, validates against VDA ISA 6.0 requirements, and flags maturity gaps automatically.

PROVE COMPLIANCE OUT
Respond to OEM Audit Requests in Hours, Not Weeks

Generate audit-ready documentation packages and supplier security evidence summaries instantly from validated data.

Related Regulations

Industries Most Impacted

Return on Investment

80%
Reduction in Evidence Collection Labor
4 Hours
To OEM Audit Package
Continuous
TISAX Label Monitoring

Key Statistics

17,500+

TISAX-assessed sites tracked with automatic label monitoring
99.2%

Evidence extraction accuracy from supplier security declarations
95%

Supplier response rate with CORA-powered campaigns

Frequently Asked Questions

What companies are subject to TISAX requirements?
Any organization handling confidential information from automotive OEMs—including Tier 1 through Tier 3 suppliers, engineering service providers, IT vendors, and logistics companies transporting prototypes—can be required to hold a TISAX label.

What are the consequences of failing a TISAX assessment?
While TISAX is not a legal regulation, failing to achieve the required label effectively blocks business with OEMs that mandate it.

How does VDA ISA 6.0 differ from previous versions?
ISA 6.0, effective April 2024, replaced the "Info High" and "Info Very High" labels with four distinct labels—Confidential, Strictly Confidential, High Availability, and Very High Availability.

What assessment formats does Certivo accept from suppliers?
Certivo accepts any format through its specialized substance reporting solutions approach: PDF certificates, Excel security questionnaires, ISO 27001 audit reports, TISAX label confirmations, XML exports, and freeform responses.

Does Certivo support TISAX alongside ISO 27001 and other security frameworks?
Yes. Certivo validates supplier security evidence against TISAX VDA ISA 6.0, ISO 27001, NIS 2, and CRA requirements simultaneously.