TISAX® Assessment: Automotive sector information security
Protect sensitive automotive information, meet OEM expectations and strengthen supply chain trust with TISAX® (Trusted Information Security Assessment eXchange).
Journey continues on Veracity, DNV's trusted digital platform.
TISAX® Assessment: Automotive sector information security
Assessment to TISAX demonstrates that your information security practices meet the requirements defined for the automotive industry. It helps you reduce risk, fulfil customer demands and avoid duplicated audits, cost and complexity.
The TISAX scheme provides a common, maturity based way to assess and demonstrate information security. It also enables efficient reuse and controlled sharing of results with multiple partners through the ENX platform.
The ENX Association is the governing body behind TISAX® and manages the TISAX program, maintains the assessment platform, and issues TISAX labels based on assessments performed by accredited assessment providers such as DNV.
What is the TISAX standard?
Applicable to suppliers, service providers and partners across the automotive industry, TISAX (Trusted Information Security Assessment eXchange) provides a maturity based approach for assessing and demonstrating information security. It is used throughout the automotive value chain in all areas where sensitive information is handled, including prototypes, design data and customer data. TISAX helps organizations establish a common, industry accepted level of information security and demonstrate it efficiently to multiple partners.
TISAX helps you achieve:
- Common recognition of assessments, reducing duplicated audits, cost and complexity across the supply chain
- Comparable and high quality assessments based on the shared VDA Information Security Assessment (ISA)
- Controlled and selective sharing of results through the ENX platform
- Clear findings and structured corrective actions that support systematic improvement
- Increased credibility and market access as TISAX is required by several OEMs and major suppliers
TISAX is built on the VDA ISA catalogue and incorporates elements of ISO/IEC 27001 Annex A controls along with relevant privacy requirements. It uses predefined assessment objectives, maturity levels and assessment levels (remote or on site), with ENX issuing labels and managing the secure exchange of results.
This structure ensures a consistent approach across the automotive sector and supports alignment with existing information security management practices.
Difference between TISAX® and ISO/IEC 27001
TISAX builds on key elements in the information security management system standard ISO/IEC 27001, with a focus on requirements specifically relevant to the automotive industry. The main differences are:
ISO/IEC 27001 |
TISAX® |
|---|---|
| Management system standard | Covers information security processes and requirements relevant to partners in the automotive industry |
| On/off approach | Maturity level approach |
| Scope defined by the organization before certification | Scope is predefined and fixed within the TISAX scheme |
| Certification body issues a certificate | ENX issues labels and manages result exchange |
| Periodic surveillance audits and recertification every 3 years | 3-year label validity with no periodic audits |
Value of TISAX assessment
Assessment to TISAX by an independent third-party such as DNV demonstrates that your organization meets the information security requirements defined in the VDA ISA. It also shows that you have practices in place to protect sensitive information shared within the automotive supply chain.
As a result, you get:
- Increased supply chain trust through recognized, industry accepted assessment results
- Improved market access as TISAX is required by several OEMs and major suppliers
- Greater efficiency by reducing duplicated audits, cost and effort across multiple partners
- Risk reduction through structured identification, remediation and validation of information security gaps
- Controlled transparency, enabling you to decide who can access your results and at what level of detail
- Objective insights from external auditors to highlight weaknesses and improvement opportunities
- Clear demonstration of commitment to protecting confidential information for stakeholders and partners
Customers
Certificates
People trained annually
Countries
Getting started for TISAX assessment
To undergo a TISAX assessment, your organization must first register as a participant with ENX and familiarize itself with the requirements defined in the VDA ISA. You then prepare by completing a self-assessment and selecting an approved audit provider.
The assessment is carried out at either Level 2 (remote) or Level 3 (on-site), depending on your scope. It includes reviewing your documented practices, clarifying potential findings and agreeing on next steps. Any identified gaps are addressed through a corrective action plan, which is followed up by the audit provider before the final report is completed.
Once assessment is finalized, the audit provider uploads the results to the ENX platform. You decide which partners can access your results, and ENX issues the relevant TISAX labels.
DNV is an assurance provider approved by the ENX Association. Through our global network of local offices and auditors, we deliver TISAX assessments and support your organization throughout the process.
As a DNV customer, you also get access to a suite of digital tools that can help you ensure compliance, continually improve and manage your entire certification journey with us.
TISAX - FAQ
-
TISAX (Trusted Information Security Assessment eXchange) is an industry accepted assessment scheme for information security in the automotive sector. It is based on the VDA Information Security Assessment (ISA) and uses predefined assessment objectives, maturity levels and labels issued by ENX to demonstrate how well an organization protects sensitive information such as prototypes, design data and customer data.
-
TISAX certification refers to the independent assessment carried out by an approved audit provider to verify that an organization meets the information security requirements defined in the VDA ISA. After the assessment, ENX issues TISAX labels that confirm the achieved security level and make the results available for controlled sharing with automotive partners. These labels are valid for three years and are widely required by OEMs and major suppliers as a condition for doing business..
-
TISAX builds on the principles of ISO/IEC 27001, but the two serve different purposes. ISO/IEC 27001 is a certifiable management system standard for establishing and maintaining an ISMS across any industry. TISAX applies these principles to the specific needs of the automotive sector, using predefined scopes, maturity based assessments and industry specific protection objectives. Instead of a certificate, ENX issues TISAX labels that can be shared with multiple partners through a central exchange.
-
Automotive certification refers to the set of standards, assessments and approvals used to ensure that organizations working with automotive manufacturers meet defined requirements for quality, safety, information security and regulatory compliance. This includes schemes such as IATF 16949 for quality management, TISAX for information security and other sector specific frameworks required by OEMs and tier suppliers. Automotive certification and assessments helps organizations demonstrate reliability, reduce risk and meet customer expectations across the global automotive supply chain.
TISAX® training
More information
Training
Relevant insight in an active learning environment.
You added value
Find out more on the digital customer experience.