Security HubTISAX Explained: What Suppliers Need

TISAX Explained: What Suppliers Need

Netru Compliance7 min read

If you supply the German automotive industry, TISAX is not optional in any practical sense. It is not a law and not quite a certification, which is exactly why it confuses people who arrive at it from an ISO 27001 background. This covers what it is, what the levels and labels mean, how much of your existing security programme counts, and what genuinely has to be built.

What TISAX is, and is not

TISAX stands for Trusted Information Security Assessment Exchange. It is operated by the ENX Association on behalf of the German automotive industry association, and it exists to solve a specific problem: every original equipment manufacturer used to audit every supplier separately, which was enormously wasteful. TISAX replaces that with one assessment whose results are shared.

The assessment is against the VDA ISA catalogue, a control set maintained by the automotive industry rather than by ISO. The catalogue draws heavily on ISO 27001 but adds requirements the industry cares about specifically, most notably around prototype protection.

It is not a certificate you publish on your website. Results are exchanged through the ENX portal, and you grant access to the customers who need to see them. This trips up marketing teams who expect a logo, and it matters commercially: your customer sees your result, the public does not.

Levels and labels

Assessment levels describe how thoroughly you are checked. The lowest is essentially a self-assessment. The middle level adds evidence review and remote interviews by an audit provider. The highest adds an on-site audit. Which level you need is set by your customer and by the protection needs of the information you handle, not by you.

Labels describe what you are assessed for. Information security is the base. Prototype protection is a separate label covering physical and organisational protection of pre-release vehicles, parts and test data, and it carries requirements that have no ISO 27001 equivalent at all: secured areas, access control to prototype zones, rules on photography, transport and events. Data protection is a third label aligned to GDPR.

You are assessed for the labels and levels your customer specifies. Guessing wrong is expensive in both directions, so get the requirement in writing before booking anything.

What ISO 27001 buys you

A great deal, and it is worth being precise. The management system, risk process, asset management, access control, supplier management, incident handling and physical security you already run map closely onto the VDA ISA catalogue. Organisations arriving with a mature ISO 27001 programme typically find the information security label is largely evidence mapping.

What it does not buy you is the assessment itself, which is a separate exercise by an ENX-approved audit provider, or the prototype protection label, which is genuinely additional work if you handle pre-release material. It also does not buy you the specific maturity expectations: VDA ISA scores controls on a maturity scale rather than present or absent, and a control you consider adequate for ISO purposes may score below the required level.

That maturity scoring is the most common surprise. ISO 27001 asks whether a control exists and operates. VDA ISA asks how well, on a defined scale, and the target is usually a three. Being certified is not the same as scoring three.

Practical planning

Results are valid for three years, so this is a recurring commitment rather than a one-off. Plan the reassessment before it becomes urgent, because audit provider availability is a real constraint in this market.

Get the required level and labels confirmed by your customer in writing before you start. Then run a gap assessment against the VDA ISA catalogue at the maturity level required, not merely against the control list, because the gap is usually maturity rather than existence.

If prototype protection is in scope, treat it as a physical security project with a separate budget and lead time. Secured areas and access control to prototype zones are construction and process work, not documentation.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call