TISAX certification 2026: Scope, test levels and effort realistically planned
TISAX is the German automotive industry’s de-facto requirement for information security in the supply chain. This article explains the scope, assessment levels, test procedure and the clean integration with ISO/IEC 27001:2022.
TISAX (Trusted Information Security Assessment Exchange) has been the German automotive industry's common testing and exchange system for information security in the supply chain since 2017, operated by the ENX Association on behalf of the Association of the Automotive Industry (VDA). Anyone who works as a supplier, engineering service provider or IT partner with German OEM groups (Volkswagen, BMW, Mercedes-Benz Group, Porsche, Audi, Stellantis Germany) is usually required to have a TISAX label with a defined assessment level. The requirements are derived from the VDA ISA catalogue (current version 6.0, published in 2024) and are based on ISO/IEC 27001:2022, but are not identical.
This article is aimed at management, ISB and information security managers who are planning TISAX 2026 for the first time or in the recertification cycle. It describes the test process, the three assessment levels (AL 1, AL 2, AL 3), the test objectives (Information Security, Confidential Information, High Availability, Data Protection, Prototype Protection), the realistic effort and the integration with an ISMS according to ISO/IEC 27001:2022. CIVAC, a compliance platform and officer-as-a-service, offers a workspace with 93 controls, 490 audit templates, EU data residency and a documented reporting line.
Key Takeaways
- TISAX is mandatory as soon as an OEM or Tier-1 requires the submission of a label and does not replace ISO/IEC 27001:2022, but rather supplements it if necessary.
- The choice of assessment level (AL 2 or AL 3) depends on the data category and the need for protection, not on the preferences of the supplier.
- Preparation usually takes 4 to 9 months. Anyone who operates an ISMS according to ISO/IEC 27001:2022 shortens the preparation considerably.
Who needs TISAX and who decides?
The obligation to obtain TISAX certification does not arise from the law, but rather from the contractual requirement of the client. OEM groups such as Volkswagen, BMW, Mercedes-Benz Group, Audi and Porsche as well as their Tier 1 suppliers require a valid TISAX label from their direct and indirect suppliers as soon as the business relationship involves the exchange of sensitive information. This applies to engineering data, prototype information, technical drawings, supplier master data and increasingly also to pure IT services such as cloud hosting and maintenance.
Who decides whether TISAX is due is the client's purchasing department in coordination with the group's internal information security department. In practice, the requirement appears in the supplier release or in the nomination letter with a specific assessment level and scope. The scope describes locations, organisational units and data categories to which the label applies. A label is valid for three years, counting from the date of successful testing by an ENX-approved auditor.
Not every supplier needs TISAX. Pure material suppliers without access to engineering data often remain outside, as do simple logistics service providers. However, as soon as an engineering order, tool construction, prototype construction or an IT interface comes into play, the label becomes obsolete. After-sales service providers with access to diagnostic data and software update paths are also increasingly being included in the TISAX scope of duties. CIVAC maintains the TISAX scope together with the ISO/IEC 27001:2022 statement in the workspace, so that multiple audits are served by the same evidence base. The role of the ISB is the operational hub and combines supplier, OEM and audit communication in one hand. The appointment certificate, signed, filed, verifiable.
Assessment levels: AL 1, AL 2, AL 3 and their test objectives
TISAX has three assessment levels with different test intensity. AL 1 is purely a self-disclosure from the supplier without external verification and in practice is only recognised in exceptional cases. AL 2 includes a remote assessment by an ENX-approved examiner, supplemented by a plausibility inspection and document review. AL 3 is an on-site assessment with extended in-depth testing, interviews and random checks of technical measures. AL 3 is typically required for high protection requirements, especially for prototype protection and high availability.
The choice of level follows the data category. Confidential information without particular sensitivity usually leads to AL 2. Data with a high or very high level of protection (Strictly Confidential, Prototype) leads to AL 3. Data related to data protection in accordance with the GDPR (data protection test objective) is possible, but in practice it is rarely the driver. High availability is required when supply chains or IT services with defined availability requirements are affected.
The scope of testing follows the VDA ISA Catalog 6.0 with currently 49 information security requirements plus optional modules for prototype protection and data protection. Each requirement is evaluated in a maturity model (levels 0 to 5), with defined minimum levels per AL. Anyone who does not reach the minimum levels will not receive a label. The measures must be documented, implemented and auditable. The examiners work with defined sampling depths, so that not every requirement is fully validated in every test, but the control and maturity assessment are. CIVAC maps the ISA requirements directly to the 93 controls according to ISO/IEC 27001:2022 and stores the evidence in the workspace. The appointment certificate, signed, filed, verifiable.
Testing process: From scoping to the label in the ENX portal
The TISAX test sequence follows a standardised phase model. Phase one is registration in the ENX portal with definition of the scope and test objectives. Phase two is the self-disclosure in the VDA ISA tool, in which the organisation documents the actual level of maturity for each requirement and supports it with evidence. Phase three is the audit by an ENX-approved auditor, depending on the AL as a remote audit or on-site appointment. Phase four is the processing of findings with action plans for deviations.
Findings are classified into two categories: Major non-conformities prevent labels from being assigned, minor non-conformities are processed with action plans. The deadline for correcting discrepancies is typically 90 days. Anyone who does not deliver within this deadline risks losing the label and status in the ENX portal. After successful completion, the auditor issues the label, which becomes visible to authorised recipients in the ENX portal. It is valid for three years.
Communication between supplier, auditor and ENX portal takes place electronically, with defined interfaces. The supplier's ISB is the single point of contact and is responsible for updating the self-disclosure, uploading evidence and tracking action plans. CIVAC offers this function on a workspace with versioning, the dual control principle and automatic reminders for ongoing measures. The auditor calls, the evidence is ready. Cross-links to adjacent roles such as Data Protection are already prepared in the workspace so that GDPR-relevant requirements from the data protection test target run without separate file management. The interface to whistleblower protection according to the HinSchG can also be managed via the same reporting channel.
VDA ISA 6.0: What the catalogue specifically requires
The VDA ISA Catalog 6.0 (Information Security Assessment) is the core content of the test. It is divided into information security with 41 mandatory requirements, prototype protection with additional physical requirements and data protection with GDPR-related testing. Information Security covers classic ISMS topics: information security policy, information security organisation, asset management, access control, cryptography, physical security, operational security, communications security, procurement and development, supplier relationships, incident management, business continuity, compliance.
Each requirement is assessed on a maturity scale. Level 0 (not implemented), Level 1 (implemented, not documented), Level 2 (documented), Level 3 (established and traceable), Level 4 (predictable), Level 5 (optimised). AL 2 usually requires level 3 as a minimum level of maturity, AL 3 requires level 3 with an increased level of proof. Anyone who remains below the minimum level of maturity in a requirement risks major non-conformity.
Prototype Protection complements physical and organisational measures: separate access areas, photo/recording bans, privacy protection, tested personnel, controlled tools, documented logistics. These measures are not included in mirror image in ISO/IEC 27001:2022 and must be implemented explicitly. CIVAC maps the 49 ISA requirements together with the 93 controls from ISO/IEC 27001:2022 and identifies the points where TISAX requires additional measures. Maturity assessments are documented in a versioned manner in the workspace and linked to evidence so that the auditor can navigate directly to the supporting file for each requirement. Updates to the VDA ISA versions (e.g. from 5.1 to 6.0) are shown differentially in the workspace and provided with adjustment recommendations. Others run compliance like a filing cabinet. We run it like software.
Interlocking with ISO/IEC 27001:2022: What is acceptable and what is not
TISAX and ISO/IEC 27001:2022 overlap substantially, but are not identical. Anyone who operates a certified ISMS according to ISO/IEC 27001:2022 with the current Annex A already covers most of the ISA requirements. Specifically, 32 of the 49 ISA requirements from information security are largely identical to Annex A controls (as of ISO 27001:2022). Seven others are partially covered. Ten requirements from Prototype Protection and some specific TISAX requirements are independent and require separate proof.
The practical consequence: Anyone who uses ISO 27001 typically saves 30 to 50 percent of the preparation effort in TISAX. Auditors accept ISO 27001 evidence as evidence provided the scope matches. However, if you don't have an ISMS, you start from the beginning and should realistically plan 6 to 9 months of preparation. A practical recommendation is to certify ISO 27001 and TISAX at the same time or in quick succession, so that the evidence base only has to be built up once.
Important: ISO 27001 is also not a TISAX replacement in the sense of the ENX portal. The label must be purchased separately because OEMs require replacement via the portal. CIVAC serves both requirements via a common workspace with 93 controls according to ISO/IEC 27001:2022 as a basis. The ISA 6.0 mapping table for Annex A 2022 is maintained and allows parallel audits without duplicate documentation. Audit proof, documented, ISO/IEC 27001:2022 proof. You can find an overview of other ISMS roles in the Rollue Overview. The combined care also saves effort in ongoing management assessment because incidents, measures and risks are recorded only once and assigned to both programs.
Effort and costs: How much preparation is realistic
The realistic effort for an initial TISAX certification depends on the starting point. If you don't have an ISMS, plan 6 to 9 months of preparation, with two to four full-time equivalents spread across ISB, IT, HR and facility. External consulting days are typically between 20 and 60. Anyone who operates an established ISMS according to ISO 27001 can complete the preparation in 3 to 5 months with reduced effort. Depending on the size and complexity, the testing costs for the ENX-approved auditor are between 8,000 and 40,000 euros for AL 2 and 15,000 to 80,000 euros for AL 3.
There are also investments in technical measures: identity and access management, endpoint protection, network segmentation, backup concepts, solutions for logging and monitoring. Physical measures, especially for prototype protection, are often investment items: access control, privacy protection, locking systems, photo prevention technology. These investments are not TISAX-specific and contribute to other compliance fields (NIS-2, ISO 27001, KRITIS, DORA).
The ongoing costs over the three-year cycle include internal audits, training, updating self-disclosure, processing OEM requests and re-certification. CIVAC reduces these costs through standardised workflows, evidence reuse across multiple compliance programs, and officer-as-a-service models. Licence the workspace for your internal representatives, or have our representatives order it. In mixed models, staffing requirements typically fall by 20 to 30 percent. Audit preparation also becomes calculable because templates, checklists and evidence samples are available and do not have to be set up again in each audit phase. This creates reliable multi-year budgets instead of peak loads in test years.
Typical findings and how they can be avoided
Recurring finding categories can be identified from testing practice. First, incomplete asset inventories: information, hardware, software and external interfaces are not fully recorded, classified and assigned to a responsible person. Second, missing or outdated risk analysis: A systematic assessment of threats and vulnerabilities is missing or not aligned with the scope. Third, incomprehensible access control: privileged access is not documented, no regular recertification of user rights.
Fourth, weakly implemented incident management: reporting channels are not defined, no documented reaction processes, no lessons learned loop. Fifthly, supplier risks not addressed: own sub-suppliers are not evaluated, contractual clauses on information security are missing, no monitoring. Sixth, business continuity is not fully developed: BIA is missing or outdated, RTO/RPO are not defined for each system, no regular tests.
Seventh, prototype protection is only partially implemented: physical measures are installed, but not secured organizationally (no photo ban, no employee obligation, no controlled logistics). Eighth, training only sporadically: awareness measures are not systematic, no documented training plan, no proof of participation. Ninth, inadequate cryptography: encryption standards are not defined, key management is not documented, expiring certificates are managed manually. Tenth, lack of data protection coordination: The data protection test objective shows gaps in the list of processing activities or in order processing. Eleventh, untested emergency plans: There are concepts, but no documented tests or lessons-learned evaluations from real incidents. Twelfth, lack of integration with NIS-2: Anyone who is subject to NIS-2 at the same time must clearly link the 24/72 reporting path to the TISAX incident obligations. CIVAC addresses these finding categories with 490 ready-to-use audit templates, automatic recertification reminders, and versioned documents. The auditor calls, the evidence is ready.
Recertification and continuous improvement
The TISAX label is valid for three years. Before expiry, a complete recertification with renewed testing by an ENX-approved auditor takes place. The effort is usually lower than for the initial certification, provided the ISMS has been maintained. On the other hand, anyone who has only set up the ISMS for the audit and then neglected it will find themselves at the beginning of the recertification process again and risk major non-conformities.
Between the audits lies operational operations: internal audits, management assessment, continuous improvement, updating self-disclosure in the event of changes, processing incidents, training, supplier assessments, compliance updates. The VDA ISA versions are updated every few years (5.1 in 2020, 6.0 in 2024), each with new or changed requirements. Anyone who loses connection begins with significant improvements in the recertification year.
CIVAC operates the ISMS as a permanent task, not as a test event. Licence the workspace for your internal representatives, or have our representatives order it. In the officer-as-a-service model, CIVAC takes over the operational ISB function with a 2 business day SLA, continuous documentation and quarterly reports to management. In this way, the label remains not only formally valid, but also materially resilient. The ENX portal entry updates automatically after a successful check, visible to all authorised OEM recipients. In the event of major scope changes (new locations, new business areas, M&A activities), a scope expansion check is carried out, which is visible as an update in the ENX portal and, if necessary, is integrated into the 3-year cycle. The management is integrated via quarterly reports and a documented management review so that strategic decisions relating to information security remain understandable and can be used as evidence in the audit.
Turn reading into a mandate.: CIVAC operationalizes TISAX
CIVAC is a compliance platform and officer-as-a-service for German companies with compliance obligations in regulated industries. The workspace manages 25 representative roles on one reporting line, with 490 ready-to-use audit templates, 93 ISO/IEC 27001:2022 controls as a platform basis, EU data residency and a documented reporting line to management. TISAX is of course based on this model because the VDA ISA mapping is prepared for ISO/IEC 27001:2022 and multiple audits use a common evidence base.
Licence the workspace for your internal representatives, or have our representatives appointed. In a typical engagement, a supplier starts with a gap assessment against VDA ISA 6.0, followed by the appointment of the information security officer (appointment certificate, signed, filed, verifiable) and a workspace provisioning within 2 working days SLA. The audit trail is maintained in the workspace, action plans run with due dates and four-eye approval. The auditor finds a complete file.
Anyone planning TISAX 2026 will gain time with an early decision. Four to six months' notice is sufficient if the workspace is set up in a structured manner and the ISB role is filled. Turn reading into an assignment. Reach the CIVAC team at info@civac.de or via the contact form on civac.de to discuss a concrete scoping plan for your TISAX cycle. You will then receive a written cost estimate with assumptions, audit trails and investment requirements. Upon request, CIVAC supports the selection of the ENX-approved auditor and the audit scheduling, including coordination with locations, stakeholders and IT deployment deadlines.
FAQ
Is TISAX required by law?
No. TISAX is a contractual requirement of the German automotive industry, not a legal requirement in the narrower sense. However, as soon as an OEM or Tier-1 requires the label, it effectively becomes mandatory because no nomination will take place without a valid label. The validity period is three years, after which full recertification by an ENX-approved auditor is required.
Is ISO/IEC 27001:2022 sufficient as a TISAX replacement?
No. ISO/IEC 27001:2022 covers a large part of the ISA requirements and significantly reduces the preparation effort, but does not replace the TISAX label in the ENX portal. OEMs require the portal entry with a defined scope. Anyone who operates both standards in parallel benefits from a common evidence base, reduced audit effort and a uniform reporting line.
Which assessment level is the right one?
The correct AL is specified by the client in the nomination letter and follows the data category. AL 2 is standard for confidential information, AL 3 for prototype data or high availability requirements. AL 1 is purely a self-disclosure and is rarely recognised in practice. The decision is not made by the supplier, but by the customer based on the agreed data categories.
How long does it take to prepare for TISAX?
Without ISMS, you expect 6 to 9 months of preparation and two to four full-time equivalents. With an established ISO/IEC 27001:2022 ISMS, you can do it in 3 to 5 months with reduced personnel requirements. CIVAC shortens the cycle through standardised templates and ISB Officer-as-a-Service with a 2 business day SLA for ordering and workspace provisioning.
How much does the TISAX exam cost?
The pure testing costs for the ENX-approved auditor are between 8,000 and 40,000 euros for AL 2 and 15,000 to 80,000 euros for AL 3, depending on the size and complexity of the scope. Preparation costs (advice, technical measures, internal resources) are typically many times higher and are the actual cost driver.
Can CIVAC provide the ISB for TISAX?
Yes. CIVAC provides a qualified information security officer as an officer-as-a-service with an appointment certificate, reporting line and 2 business day SLA. The model can be combined with internal responsible persons: Licence the workspace for your internal representatives, or have our representatives appointed. In the mixed model, CIVAC often takes over the audit preparation and maintenance of the self-disclosure.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.