TISAX Certification Consulting: From Scoping to Label in 6 to 9 Months
TISAX is mandatory for most automotive suppliers handling OEM information. This guide explains assessment levels, the VDA ISA 6 catalogue, realistic timelines, audit costs and where structured consulting cuts the path to the label from twelve months to under nine.
TISAX, the Trusted Information Security Assessment Exchange, has become the de facto information security standard for the European automotive supply chain. The catalogue underpinning it, VDA ISA 6, was released by the German Association of the Automotive Industry in 2024 and aligns closely with ISO/IEC 27001:2022. Without a valid TISAX label, suppliers are routinely locked out of OEM tenders by Volkswagen, BMW, Mercedes-Benz, Audi, Porsche and most Tier-1 manufacturers.
This article walks you through what TISAX consulting actually covers: scoping, assessment-level selection, gap analysis against VDA ISA 6, remediation, ENX portal registration, and the audit itself. It also explains where external support adds value, where it does not, and how CIVAC supports the process as a compliance platform and officer-as-a-service provider with EU data residency and audit-ready templates.
Auf einen Blick
- TISAX uses three assessment levels (AL1 to AL3) and the VDA ISA 6 control catalogue, all administered through the ENX portal.
- Realistic timelines run from six to nine months for AL2 and nine to twelve months for AL3, including audit scheduling.
- Consulting fees and audit fees are separate: budget 30k to 90k EUR for AL2, 60k to 150k EUR for AL3, plus internal effort.
What TISAX Is and Why It Matters
TISAX is an information security assessment and exchange mechanism operated by the ENX Association on behalf of the VDA. It allows automotive suppliers to undergo a single assessment and share the result with multiple OEMs and Tier-1 manufacturers through the ENX portal, instead of being audited repeatedly by each customer.
The mechanism rests on the VDA ISA catalogue, currently in version 6 (April 2024). VDA ISA 6 contains controls for information security, prototype protection and data protection. It maps closely to ISO/IEC 27001:2022 Annex A, but adds automotive-specific requirements, especially around prototype handling and supplier governance.
The label is granted by audit providers accredited by ENX, not by ENX itself. Recognised providers include TUV NORD, TUV Rheinland, DEKRA, DQS and PwC, among others. The audit result is uploaded to the ENX portal, where OEMs can review the assessment level, scope and result for any registered supplier.
Without a valid label, suppliers cannot bid on most automotive contracts that involve confidential OEM information, prototype data or development collaboration. Existing contracts often contain clauses requiring TISAX renewal every three years. Lapsing labels can trigger contractual penalties or de-listing from supplier portals.
Beyond the automotive sector, TISAX is increasingly recognised by aerospace, defense and rail suppliers who already operate ISO/IEC 27001:2022. The overlap between both frameworks means a properly designed ISMS covers roughly 80 percent of TISAX requirements out of the box, with the remaining 20 percent driven by automotive-specific controls.
For most suppliers, the question is no longer whether to certify, but at which level and on what timeline. The platform-and-officer combination that CIVAC offers handles both the strategic decision and the operational execution.
Assessment Levels: AL1, AL2, AL3
TISAX defines three assessment levels with increasing audit rigor. AL1 is rarely used and based on a self-assessment alone. It applies only to scopes with limited confidentiality requirements and is generally not accepted by major OEMs for production suppliers.
AL2 is the standard for handling confidential information and most prototype-adjacent activities. It combines a self-assessment with a remote plausibility check by the audit provider, supported by document review and interviews. Most Tier-2 and Tier-3 suppliers obtain AL2 labels.
AL3 covers strictly confidential information, prototypes under heightened protection (e.g. design studies, unreleased models) and high-availability scenarios. It includes an on-site audit at all relevant sites, often with physical security tests. Tier-1 suppliers, engineering service providers and prototype manufacturers typically need AL3.
The choice of level is driven by the customer requirement. OEMs publish their expectations either in supplier portals or in contractual annexes. Some require AL3 for any prototype access, others accept AL2 with additional safeguards. Misjudging the required level leads to audit rework and lost months of project time.
Within one supplier organisation, multiple labels can coexist: one location with AL2 for series production, another with AL3 for development. Each label has its own scope, its own assessment objectives and its own validity period of three years.
Good consulting starts with a customer-requirement matrix: which OEMs, which contracts, which information categories, which sites. The output is a level recommendation per scope, plus a roadmap for sequencing the assessments. Bestellurkunde, unterschrieben, abgelegt, belegbar applies here too: every scope decision must be documented and signed off by the appropriate executive.
VDA ISA 6: What Changed and What It Means
VDA ISA 6 was released in April 2024 and is the binding catalogue for all TISAX assessments starting in 2025. It contains roughly 50 information security controls, plus separate modules for prototype protection and data protection. The structure aligns more closely with ISO/IEC 27001:2022 Annex A than previous versions, which simplifies dual-track ISMS programmes.
Key changes from VDA ISA 5 to 6 include: tighter requirements on incident response and reporting (aligned to NIS-2 timelines where relevant), refined supply-chain due diligence controls, explicit cloud-service-provider governance, and stronger expectations on identity and access management for privileged accounts.
The catalogue uses a maturity model: each control is scored from level 0 (incomplete) to level 5 (optimising), with level 3 (established) typically required for AL2 and level 3 or 4 for AL3 depending on the control. Lower maturity is acceptable only with documented justification and compensating controls.
Each control demands evidence: policies, procedure documents, system configurations, training records, incident logs. Evidence must be current, version-controlled and traceable to the responsible owner. Auditors test evidence through interviews, document samples and, at AL3, on-site walkthroughs.
The prototype protection module covers physical security, access controls, transport, photography restrictions and reporting of prototype incidents. The data protection module aligns with GDPR but adds automotive-specific scenarios such as connected-vehicle data flows and engineering data of natural persons.
Maintaining VDA ISA 6 alignment is an ongoing task, not a one-off project. Controls evolve, OEM expectations shift, and the ENX Association publishes interpretation updates. A workspace that tracks control maturity, evidence freshness and owner accountability turns continuous compliance into a managed process rather than an annual fire drill.
Scoping: The Decision That Drives Everything
Scoping is the single most impactful decision in a TISAX programme. It defines which sites, which processes and which information categories are in scope, and therefore drives audit duration, cost and remediation effort. A bloated scope wastes money; an underscoped programme fails customer requirements.
The standard scope template, published by ENX, lists assessment objectives such as Info high, Info very high, Proto, Data, AL2 or AL3. Each objective triggers specific control sets within VDA ISA 6. Consultants help map customer requirements to objectives, then translate objectives into a defensible scope statement.
Common scoping mistakes include: pulling unrelated business units into scope because they share a building, excluding subsidiaries that handle OEM data informally, ignoring cloud services where confidential information is processed, and failing to account for home-office and mobile work scenarios introduced after 2020.
Sites are scoped individually. A multi-site supplier with three German plants, one Polish plant and one French sales office typically declares each site separately on the ENX portal. Audits cover all in-scope sites, often through a combination of central audit at headquarters and sampling at production sites.
The scope is binding once registered. Changes during the assessment cycle require formal updates on the ENX portal and may trigger additional audit days. A clean initial scope, validated by both consultant and the appointed information security officer, prevents the most expensive form of rework.
CIVAC supports scoping by mapping customer contracts, information categories and physical locations to assessment objectives within the workspace. The output is a scope statement ready for ENX registration, with full traceability back to contractual and regulatory drivers. License the workspace for your internal officers, or appoint our officers instead.
Gap Analysis and Remediation
The gap analysis compares the current state of the ISMS against the required maturity level per control in VDA ISA 6. It produces a list of findings, each categorised by severity (critical, major, minor) and assigned to a responsible owner with a remediation deadline.
Typical gap categories include: incomplete asset inventory, missing or outdated information classification policy, weak supplier governance, insufficient incident response documentation, gaps in privileged access management, and inadequate prototype handling procedures. Each gap maps to one or more specific VDA ISA 6 controls.
Remediation effort varies dramatically. Updating policies and producing missing evidence is fast (days to weeks). Building new processes (e.g. supplier-risk reviews) takes weeks to months. Closing technical gaps (e.g. PAM implementation, network segmentation, SIEM rollout) can take six to twelve months and requires coordination with IT operations.
Realistic project plans phase remediation across three streams: documentation (low effort, high audit visibility), process maturity (medium effort, medium audit visibility) and technical controls (high effort, sometimes invisible until tested). Phasing prevents the common failure mode of finishing documentation while technical evidence still fails.
The remediation plan must be approved by executive management and resourced accordingly. TISAX assumes management commitment; auditors test this through interviews and by reviewing the appointment of an information security officer with a clear reporting line. Berichtslinie an die Geschäftsleitung is not optional.
CIVAC delivers 490 audit-ready templates and a gap-analysis structure aligned to VDA ISA 6. Findings, owners, deadlines and evidence sit in one workspace. Andere führen Compliance wie einen Aktenschrank. Wir führen sie wie Software, with searchable evidence, version history and an audit trail that survives staff turnover.
ENX Portal and Audit Provider Selection
Every TISAX assessment is registered on the ENX portal at enx.com. Registration requires company data, scope declaration, assessment objectives, level selection and the choice of an audit provider. The portal fee is published by ENX and depends on the assessment scope and level.
Audit providers accredited by ENX include TUV NORD, TUV Rheinland, DEKRA, DQS, PwC, KPMG and several specialised firms. Selection criteria include sector experience, language coverage for multi-site assessments, availability (lead times of three to six months are common in busy quarters), and rate cards.
Audit fees scale with assessment level, number of sites and complexity. For AL2 with one site, audit fees typically run between 8.000 and 18.000 EUR. For AL3 with multiple sites, audit fees can reach 30.000 to 60.000 EUR or more. Travel costs are usually added separately.
The audit itself follows a defined sequence: opening meeting, document review, interviews, evidence sampling, optional on-site walk-through (AL3), closing meeting with preliminary findings. The audit report is finalised within four to six weeks and uploaded to the ENX portal once any minor findings are closed.
Findings are categorised as observations, minor non-conformities or major non-conformities. Majors must be closed before the label is issued. Minors can be closed within a defined grace period (often 90 days), with evidence reviewed remotely. Observations are non-binding but should be addressed before the next assessment cycle.
The label is valid for three years. Surveillance is event-driven rather than annual: significant scope changes or major incidents may trigger re-assessment. Continuous evidence collection is therefore essential. Der Prüfer ruft an, der Nachweis liegt bereit holds for TISAX as much as for any other audit regime.
TISAX vs. ISO 27001: Where They Overlap, Where They Diverge
ISO/IEC 27001:2022 and TISAX share roughly 80 percent of their control content. VDA ISA 6 explicitly references ISO/IEC 27001 in its structure, and most controls map one-to-one or one-to-many between the two frameworks. Suppliers already certified to ISO 27001 typically need 6 to 9 months to add a TISAX label, instead of 12 to 18 months from scratch.
The main differences are automotive-specific: prototype protection (no ISO equivalent), heightened supply-chain due diligence requirements, specific physical security rules for development sites, and tighter expectations around connected-vehicle data flows. These gaps are real but bounded; they do not require a separate ISMS.
Operating both frameworks under one ISMS is the standard approach for serious suppliers. A combined Statement of Applicability covers ISO Annex A controls, with VDA ISA 6 extensions documented as additional controls or as policy attachments. The ISMS scope can be defined to cover ISO certification and TISAX assessment simultaneously.
For suppliers operating internationally, ISO 27001 remains the master certification because it is recognised globally. TISAX adds an automotive-specific layer that customers in the European OEM ecosystem demand. Suppliers serving only European automotive customers can in principle skip ISO 27001, but most use both.
The ISO/IEC 27001:2022 transition deadline is October 2026. Suppliers who renew or extend their certifications in 2025 or 2026 should align both updates: the ISO update and the VDA ISA 6 alignment. Doing both at once reduces internal disruption and audit fatigue.
CIVAC maps controls automatically between ISO Annex A, VDA ISA 6, NIS-2 requirements and DSGVO obligations. Audit-fest, dokumentiert, paragraphenfest works regardless of which framework the auditor opens with.
Realistic Timelines, Costs and Internal Effort
Realistic timelines depend on starting maturity. A supplier with an existing ISO 27001-certified ISMS needs 6 to 9 months to reach AL2 and 9 to 12 months to reach AL3. A supplier with no ISMS at all needs 12 to 18 months for AL2 and 18 to 24 months for AL3, sometimes longer if technical infrastructure requires rebuilding.
Total programme costs break down into consulting fees, internal effort and audit fees. Consulting fees for a mid-sized supplier targeting AL2 run between 30.000 and 60.000 EUR, for AL3 between 60.000 and 120.000 EUR. Internal effort is typically 0.5 to 1.5 full-time-equivalent over the project duration, depending on technical remediation needs.
Audit fees are paid separately to the audit provider and added on top: 8.000 to 18.000 EUR for AL2, 30.000 to 60.000 EUR for AL3 with multiple sites. The ENX portal registration fee is several hundred euros per scope and is updated periodically by the ENX Association.
Hidden costs that catch first-timers off-guard include: tooling investments (SIEM, PAM, asset management), physical security upgrades (locked development areas, badge systems), training programmes for the entire workforce, and management-system documentation production.
Renewal is less expensive than initial certification, typically 40 to 60 percent of the original consulting fee and similar audit fees. Continuous evidence collection through the workspace approach reduces renewal effort further because the audit trail is already complete.
Sustainable TISAX compliance requires an information security officer with the time, mandate and reporting line to operate the ISMS. License the CIVAC workspace for your internal ISO, or appoint our ISO instead. The two-business-day SLA on the appointment letter is independent of consulting engagement size.
From Reading to Engagement: How CIVAC Supports the Path
TISAX consulting that delivers a label on schedule combines methodology with operational tooling. The methodology is well-defined by VDA ISA 6 and the ENX framework. The operational layer, where most programmes lose time, is the gap between knowing what to do and proving it on audit day. That gap is what the CIVAC platform closes.
The platform ships with 490 audit-ready templates, including information security policy, asset inventory, supplier risk assessment, incident response procedure, prototype handling procedure and management review minutes. Each template is structured to satisfy VDA ISA 6 controls and ISO/IEC 27001:2022 Annex A in parallel.
Officer-as-a-service is the second option. CIVAC appoints a qualified information security officer for your organisation, with the appointment letter (Bestellurkunde) delivered within two business days. The officer operates within the same workspace, attends management reviews, and provides the reporting line that auditors expect to see.
License the workspace for your internal officers, or appoint our officers instead. Both models are interoperable. If you start with an external officer and later hire internally, the workspace, evidence and policies transfer without friction. The data remains on EU infrastructure throughout, satisfying both DSGVO and TISAX data residency expectations.
A typical engagement begins with a two- to four-week scoping and gap-analysis sprint. The output is a budgetable roadmap covering scope decisions, level recommendations, audit-provider shortlist, remediation backlog and a realistic timeline to label issuance. From there, execution follows a workspace-driven cadence with measurable milestones.
Aus dem Lesen einen Auftrag machen. Write to info@civac.de or use the contact form at civac.de. We will respond with a proposal for the initial scoping sprint and an indicative timeline to your TISAX label.
FAQ
Do you have to be certified to ISO 27001 before pursuing TISAX?
No. ISO/IEC 27001:2022 certification is not a prerequisite for a TISAX label. However, the overlap between both frameworks is roughly 80 percent. Suppliers with an existing ISO 27001 ISMS typically reach TISAX in half the time compared with starting from scratch, because most controls are already in place.
How long is a TISAX label valid?
A TISAX label is valid for three years. Surveillance is event-driven, meaning significant scope changes, major security incidents or contractual triggers can require an interim reassessment. Most suppliers begin renewal preparations 9 to 12 months before expiry to avoid gaps in their portal listing.
Which assessment level should an automotive supplier choose?
The level is driven by customer requirements and the type of information handled. AL2 covers confidential information for most Tier-2 and Tier-3 suppliers. AL3 is required for strictly confidential information, prototype protection and high-availability scenarios. Verify the requirement with each OEM customer before scoping.
What is VDA ISA 6 and how does it differ from VDA ISA 5?
VDA ISA 6 is the control catalogue released in April 2024, mandatory for assessments from 2025 onward. Key changes from version 5 include stronger alignment to ISO/IEC 27001:2022, refined supply-chain controls, explicit cloud-governance requirements and tighter incident-response expectations aligned with NIS-2 timelines where relevant.
Can a TISAX assessment cover multiple sites in one audit?
Yes, but each site must be declared separately on the ENX portal and is audited individually. Audit providers often combine sites into a single engagement, with a central audit at headquarters and sampling at production sites. Multi-site scopes increase audit days and cost proportionally.
What happens if the audit identifies major non-conformities?
Major non-conformities must be resolved before the label is issued. The audit provider verifies remediation through follow-up review, often remote. Minor non-conformities allow label issuance with a grace period, typically 90 days. Observations are non-binding but should be addressed before the next assessment cycle.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.