What is TISAX?

TISAX was developed to create a standardized and scalable approach to information security in the automotive industry. It is based on the Information Security Assessment (ISA) catalogue which is maintained by the ENX Association and published by the VDA.
Design data, production information, customer information, prototypes, and intellectual property all need to be protected. Beside securing information, the ISA helps companies to make their supply chains more resilient and to keep their businesses running.
In the past, companies tried to verify this through individual supplier audits or general requirement catalogues. These approaches were inefficient, difficult to scale, and often led to inconsistent results.
TISAX provides a shared framework for assessments and recognition across the industry. TISAX with its requirements, third party audits, and its exchange mechanism provides a consistent trustworthy proof of assessed Information Security Management Systems (ISMS). TISAX helps to identify risks, implement protection measures, and respond effectively to incidents.
Supply Chain Management
Manage cyber risks across a large number of business partners through an established system consistently focused on supply chain risk management. TISAX is one of the world's largest assessment standards and the largest for industrial value chains. With TISAX, we create an assurance infrastructure that strengthens the resilience of supply chains in Germany, Europe, and worldwide. Become part of TISAX.
Read more about Managing Security Risks of Business Partners…

TISAX Process and Exchange

1. Registration
Registration of a TISAX Participant and at least one TISAX Assessment Scope.

2. Selection
After a successful registration you can choose a TISAX Audit Provider for your TISAX Assessment.

3. Assessment
Undergoing an TISAX Assessment.

4. Exchange
Exchange of the TISAX Assessment results with existing and potential partners within TISAX.

TISAX combines a structured assessment process with a secure exchange platform, the ENX Portal.
The process begins with registration, where companies define their assessment scope. This includes relevant locations, processes, and protection needs.
After registration, a company selects an approved audit provider. The assessment starts with a self-assessment based on the ISA Catalogue and is followed by an external audit. Depending on the level of protection required, this may range from document reviews to detailed on-site inspections.
The results are provided in a standardized format and issued as TISAX labels, which reflect the specific assessment objectives such as information security, data protection, or prototype protection. These labels are valid for three years.
A central element of TISAX is the ENX Portal, which enables companies to securely share their results with selected partners. Results are not publicly available, ensuring full control and confidentiality.
This structured approach makes TISAX efficient, comparable, and scalable across the entire automotive ecosystem. To understand the process in detail we recommend to have a look in our TISAX Participant Handbook.
Further information

Developed by the industry
Governed by the ENX Association, TISAX is continuously developed by automotive manufacturers, suppliers, and audit providers working together in expert groups and committees.

Information Security Assessment
The Information Security Assessment (ISA) is an information security requirements catalogue that is aligned with other big standards. It is used by companies both for internal purposes as well as assessments by suppliers and service providers which are part of the automotive supply chain.

Global audit providers
TISAX assessments are conducted worldwide by independent Audit Providers. Centralized governance ensures consistent assessments and comparable results across providers.
TISAX Registration & Process
Have a look in our video that explains how the TISAX registration process works in detail.
More information about the TISAX process can also be found in the TISAX Participant Handbook.
