Quick answer

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standard security assessment, governed by the ENX Association and based on the German automotive association's ISA catalog. European OEMs (Volkswagen, BMW, Mercedes-Benz, and their tier-one suppliers) require a TISAX label before sharing sensitive information: designs, prototypes, production data, with a supplier. One assessment by an accredited provider yields labels shared through the ENX platform with every participant, replacing per-OEM audits.

Assessment levels and labels

TISAX scopes by the sensitivity of what you handle:

  • Assessment Level 2 (AL2): for high protection needs; a plausibility check of your self-assessment with remote evidence review.
  • Assessment Level 3 (AL3): for very high protection needs (prototype data, strictly confidential information); an on-site audit with interviews.
  • Labels certify specific scopes: information security with high or very high protection needs, prototype protection, and data protection modules. Your customer's requirement dictates which labels and level you need; labels are valid three years.

The ISA catalog underneath is ISO 27001-shaped (ISMS structure, risk treatment, access control, supplier management) with automotive-specific additions, most notably prototype and project confidentiality protection, and a maturity-level scoring model where target maturity must be reached per control.

Who needs it in practice

Anyone in the European automotive data chain: engineering service providers, software vendors whose products process vehicle or production data, logistics and marketing agencies handling unreleased-model material, and cloud services hosting any of it. The trigger is contractual: an OEM or tier-one procurement gate that says "TISAX label required," often with a deadline that makes an efficient path to assessment commercially urgent.

Relationship to ISO 27001

An existing ISO 27001 ISMS covers most of the ISA catalog's substance; the deltas are the automotive-specific controls, the maturity scoring model, and assessment mechanics. Companies with a working ISMS typically reach TISAX readiness as an extension project, not a rebuild, which is exactly how cross-mapped platforms treat it.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.