# TISAX (Trusted Information Security Assessment Exchange) Compliance

## Your OEM Just Required TISAX AL3. Can You Prove Information Security Across Every Supplier Site?

TISAX compliance demands maturity level 3 across every VDA ISA control—with evidence from every supplier handling confidential data. VDA ISA 6.0 now splits labels into Confidentiality and Availability. Most OEMs require on-site AL3 assessments. Audit-ready evidence across your supply chain is mandatory.

Certivo automates supplier security evidence collection from declaration to audit-ready documentation.

17,500+

Sites assessed across 90+ countries

3 years

TISAX label validity period before reassessment

Level 3

Minimum maturity required across all VDA ISA controls

## Regulation Overview

**Jurisdiction**  
Global (originated in Germany; required across the global automotive supply chain)  
**Regulatory Body**  
ENX Association (on behalf of the German Association of the Automotive Industry / VDA)  
**Regulation Number**  
VDA ISA 6.0 (effective April 1, 2024)  
**Effective Date**  
TISAX launched 2017; ISA 6.0 mandatory for all new assessments from April 1, 2024  
**Official Source**  
[ENX Portal](https://portal.enx.com/en-us/tisax/)  
**Key Threshold**  
Maturity Level 3 minimum across all applicable VDA ISA control questions

# What is TISAX?

TISAX is the automotive industry's standardized information security assessment and exchange mechanism and the cornerstone of OEM supplier qualification requirements. For supply chain teams, the primary obligation is demonstrating information security maturity across confidentiality, availability, prototype protection, and data privacy—validated through an ENX-approved audit provider.

Over 17,500 sites across 90+ countries hold active TISAX labels as of 2025. VDA ISA 6.0, effective April 2024, replaced the previous label structure with four distinct labels: Confidential, Strictly Confidential, High Availability, and Very High Availability. OEMs including Volkswagen, BMW, Stellantis, and PACCAR now mandate TISAX as a prerequisite for RFQ participation and ongoing supply chain engagement.

TISAX compliance requires documented evidence of a functioning ISMS—policies, risk assessments, access controls, and incident response—from every supplier site handling OEM data. When VDA updates the ISA catalog, your entire security management system requires reassessment against the new controls.

## Key Components / Sub-Frameworks

**Obligation**  
Defines all control questions and maturity targets for assessment  
**VDA ISA Catalog**  
Information Security Assessment questionnaire (currently v6.0)  
**Obligation**  
OEM requirement determines level; most require AL3 for confidential data  
**Assessment Levels (AL1–AL3)**  
Tiered audit depth from self-assessment to on-site inspection  
**Obligation**  
Protects trade secrets, design data, and proprietary specifications  
**Confidentiality Labels**  
Confidential / Strictly Confidential (replaced Info High / Very High)  
**Obligation**  
Ensures supplier IT/OT resilience against ransomware and disruption  
**Availability Labels**  
High Availability / Very High Availability  
**Obligation**  
Required for suppliers handling prototypes, test vehicles, or design data  
**Prototype Protection**  
Physical and organizational safeguards for pre-production components  
**Obligation**  
Mandatory for suppliers processing personal data on behalf of OEMs  
**Data Protection**  
Personal data handling requirements beyond GDPR baseline

## Key Compliance Requirements

# Who Must Comply
- Tier 1, Tier 2, and Tier 3 suppliers handling confidential OEM information
- Service providers processing automotive design, engineering, or production data
- IT and software vendors integrated into automotive development environments
- Logistics providers transporting prototypes or sensitive components
- Non-European companies supplying into European OEM supply chains
- Contract manufacturers and assembly partners with OEM data access

# Key Thresholds

**Maturity Level 3**  
Minimum score required per VDA ISA control question for label issuance  
**AL3 (Assessment Level 3)**  
On-site audit required for very high protection needs—most OEM standard  
**3 years**  
TISAX label validity period before mandatory reassessment  
**6–12 months**  
Typical implementation timeline for organizations without existing ISMS

## Core Obligations

1. **ISMS Implementation**  
   Establish and maintain an Information Security Management System per VDA ISA  
   **DEADLINE**  
   Before assessment registration  
2. **VDA ISA Self-Assessment**  
   Complete the full ISA questionnaire and document maturity levels per control  
   **DEADLINE**  
   Before engaging audit provider  
3. **ENX Portal Registration**  
   Register as TISAX participant, define scopes, locations, and assessment objectives  
   **DEADLINE**  
   Before ordering assessment  
4. **External Assessment**  
   Undergo AL2 (remote) or AL3 (on-site) audit by ENX-approved audit provider  
   **DEADLINE**  
   Per OEM contractual timelines  
5. **Supply Chain Flowdown**  
   Ensure sub-tier suppliers meet comparable information security standards  
   **DEADLINE**  
   Ongoing

## TISAX-Specific Pain Points

**The Multi-Site Evidence Scramble**  
Your OEM requires AL3 across four manufacturing sites and two engineering centers. Each site needs its own VDA ISA self-assessment, but ISMS documentation lives in different systems, different languages, and different formats.

**The Maturity Level Gap**  
The auditor scores your incident response process at maturity level 2—documented but not consistently practiced.

**The Sub-Tier Visibility Problem**  
TISAX requires you to assess and manage information security risks from your own suppliers.

**The ISA 6.0 Transition Burden**  
VDA ISA 6.0 split the Information Security label into four separate objectives. Six new control questions target ransomware defense and business continuity.

## Certivo in Action

### Certivo Workflow

**GET EVIDENCE IN**  
Collect Security Evidence from Every Supplier—Without the Chasing

CORA launches targeted campaigns to collect ISMS documentation, security questionnaire responses, and TISAX label status from your entire supplier base, follows up automatically, and accepts responses in any format.

- Launch information security campaigns to hundreds of suppliers with one click
- CORA-powered outreach in suppliers' native languages
- Accept any format: PDFs, Excel questionnaires, ISO 27001 certificates, TISAX label screenshots
- Track response rates and escalate non-responders automatically

**MAKE SENSE OF IT**  
Know Instantly Where Supplier Security Gaps Exist Across Your Network

CORA parses every supplier submission, extracts security control evidence, validates against VDA ISA 6.0 requirements, and flags maturity gaps automatically.

- Automatic validation against all VDA ISA 6.0 control questions
- Real-time alerts when supplier TISAX labels approach expiration

**PROVE COMPLIANCE OUT**  
Respond to OEM Audit Requests in Hours, Not Weeks

Generate audit-ready documentation packages and supplier security evidence summaries instantly from validated data.

## Related Regulations

- **ISO 27001**  
  TISAX builds on ISO 27001 with automotive-specific additions; ~70% control overlap  
- **IATF 16949**  
  IATF requires consideration of information security and contingency planning  
- **NIS 2 Directive**  
  EU cybersecurity directive; ENX confirms TISAX meets all relevant NIS 2 requirements  
- **EU GDPR**  
  TISAX data protection module addresses personal data handling beyond GDPR baseline  
- **EU Cyber Resilience Act**  
  CRA requires cybersecurity for products with digital elements; TISAX addresses supply chain security  
- **UNECE WP.29 / R155**  
  UN vehicle cybersecurity regulation requiring CSMS across the supply chain

## Industries Most Impacted

## Return on Investment

**80%**  
Reduction in Evidence Collection Labor  
**4 Hours**  
To OEM Audit Package  
**Continuous**  
TISAX Label Monitoring

## Key Statistics

17,500+

TISAX-assessed sites tracked with automatic label monitoring  
99.2%

Evidence extraction accuracy from supplier security declarations  
95%

Supplier response rate with CORA-powered campaigns

## Frequently Asked Questions

**What companies are subject to TISAX requirements?**  
Any organization handling confidential information from automotive OEMs—including Tier 1 through Tier 3 suppliers, engineering service providers, IT vendors, and logistics companies transporting prototypes—can be required to hold a TISAX label.

**What are the consequences of failing a TISAX assessment?**  
While TISAX is not a legal regulation, failing to achieve the required label effectively blocks business with OEMs that mandate it.

**How does VDA ISA 6.0 differ from previous versions?**  
ISA 6.0, effective April 2024, replaced the "Info High" and "Info Very High" labels with four distinct labels—Confidential, Strictly Confidential, High Availability, and Very High Availability.

**What assessment formats does Certivo accept from suppliers?**  
Certivo accepts any format through its specialized substance reporting solutions approach: PDF certificates, Excel security questionnaires, ISO 27001 audit reports, TISAX label confirmations, XML exports, and freeform responses.

**Does Certivo support TISAX alongside ISO 27001 and other security frameworks?**  
Yes. Certivo validates supplier security evidence against TISAX VDA ISA 6.0, ISO 27001, NIS 2, and CRA requirements simultaneously.
