77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
TISAX certification for automotive suppliers: obligations, stages, preparation
IT Security & NIS-2

TISAX certification for automotive suppliers: obligations, stages, preparation

29 August 202613 min readBy Lena Vogt
CIVAC

OEMs require TISAX as a prerequisite for orders. This guide explains labels, assessment levels, VDA-ISA-6 controls and operational preparation for automotive suppliers in Germany and the DACH region.

TISAX (Trusted Information Security Assessment Exchange) has been the binding testing standard for information security in the automotive supply chain since 2017 and has been based on the VDA ISA Catalog 6.0 since 2024. Suppliers who process development data, prototypes or personal data from OEMs will not be eligible for the award without a valid TISAX label. The listing is carried out by the ENX Association and is valid for three years.

This article shows which assessment levels (AL 1, AL 2, AL 3) are required for which protection needs, how the VDA-ISA-6 control catalogue interacts with ISO/IEC 27001:2022 and which operational steps a supplier must complete in the 90 days before the audit. You will learn how CIVAC, as a compliance platform and officer-as-a-service, shortens preparation and stores evidence in an audit-proof manner.

Key Takeaways

  • The TISAX label is valid for three years and is a prerequisite for listing with almost all German OEMs.
  • VDA ISA 6.0 requires 41 information security controls, supplemented by prototype protection and data protection modules.
  • AL 2 (remote plausibility check) is sufficient for standard data, AL 3 (on-site audit) is mandatory for high protection requirements and prototypes.

TISAX at a glance: standard, carrier, scope

TISAX was introduced in 2017 by the Association of the Automotive Industry (VDA) and the ENX Association and replaces the previously bilateral supplier audits. The standard is based on the VDA Information Security Assessment, which is currently valid in version 6.0 (publication 2024) and is closely based on ISO/IEC 27001:2022.

The test is carried out by accredited audit providers such as DQS, TÜV Süd or Bureau Veritas. Results are published on the ENX platform with defined labels (e.g. “Info high”, “Prototypes”, “Data protection”) so that every OEM can view the status of their suppliers.

All companies along the automotive value chain are addressed: Tier 1 suppliers, Tier 2 component manufacturers, engineering service providers, logistics providers, IT providers and tooling specialists. Pure software and telematics providers are also affected today.

The scope is determined per location and per data category. A supplier with a factory in Stuttgart and a development centre in Sindelfingen usually requires two separate assessments. There is no blanket group certification.

Those who use the CIVAC workspace store a structured scope definition, location list and data categories. The Information Security Officer controls the process from the scoping session to the audit date.

Others run compliance like a filing cabinet. We run it like software.

VDA ISA 6.0: 41 controls, three modules, one logic

The VDA ISA Catalog 6.0 contains 41 information security requirements, divided into seven chapters: information security policies, organisation, personnel security, physical security, identity and access management, IT security as well as supplier and provider relationships.

Two additional modules are optionally added: prototype protection (chapter 8, 22 requirements) and data protection (chapter 9, 4 requirements). Both modules are only checked if the OEM requests this in the order or if personal data is processed.

Each requirement is rated on a maturity scale from 0 (incomplete) to 5 (optimizing). The target maturity level is 3 (established). Maturity levels below 3 are considered deviations and must be closed in the action plan.

The overlap with ISO/IEC 27001:2022 is high: Anyone who operates a certified ISMS with the 93 Annex A controls covers an estimated 70 percent of the VDA-ISA requirements. The gap typically affects prototype protection, supplier control and concrete classification rules.

CIVAC provides 490 audit templates, including maturity tracker, action plan and stakeholder map. If you want to supplement an existing ISMS, you will find a preconfigured mapping VDA ISA to ISO 27001 in the module for the Information Security Role.

Audit-proof, documented, VDA-ISA-6-proof.

Assessment level AL 1, AL 2, AL 3: If which level?

TISAX has three assessment levels. AL 1 is a pure self-disclosure without external verification and is only accepted in rare cases, for example for uncritical administrative data without personal reference.

AL 2 includes a self-disclosure plus a plausibility check by the auditor, usually remotely via video conference and document review. AL 2 covers standard data with a high level of protection, such as construction data without prototype status.

AL 3 requires an on-site inspection with an inspection of the properties, random samples in productive systems and interviews with key roles. AL 3 is mandatory for very high protection requirements, prototype protection and special personal data.

The choice of level is determined by the OEM, not the supplier. Anyone who works for several OEMs should implement the highest required level because multiple audits double the costs. An AL-3 label is recognised by OEMs that only require AL 2.

Typical effort in practice: AL 2 requires four to six months of preparation, AL 3 between six and twelve months. Depending on the size of the location, the audit costs are between 8,000 and 25,000 euros net, plus internal expenses.

CIVAC shortens the preparation process using ready-made guidelines and a guided maturity check. The workspace documents the gap analysis, action plan and those responsible in an audit-proof manner.

Prototype Protection: The module that overturns most audits

The prototype protection module (Chapter 8 of the VDA ISA) is the most common stumbling block. It requires physical protection zones, access control with multi-factor authentication, photo and cell phone bans, isolated workshop areas and documented transport processes.

Specific evidence to be provided includes, among other things: door locks for test vehicles, camouflage requirements for road tests, separate painting and assembly lines, tamper-proof packaging during shipping and recorded destruction after the end of the project.

The module takes effect as soon as the Supplier has pre-series components, test vehicles, design models or prototypes in his area of responsibility. Pure data transport (CAD models of uncamouflaged vehicles) also trigger the need for protection.

Auditors check on site and unannounced as part of the AL-3 audit. A lack of camera surveillance at delivery gates or an open WLAN in the workshop area regularly leads to major findings that block the label.

CIVAC provides a pre-configured prototype protection guideline, a training document for the workforce and a checklist for the physical inspection. The safety concept, inspection log and proof of training are stored centrally in the workspace.

The auditor calls, the evidence is ready.

Data protection module: GDPR meets VDA ISA

The data protection module (Chapter 9) is mandatory as soon as the supplier processes personal data from the OEMs, such as telematics data from connected car services, employee data from work contracts or customer data from after-sales processes.

Four core requirements are checked: documented legal basis, order processing contracts according to Art. 28 GDPR, technical and organisational measures and reporting channels for data breaches according to Art. 33 GDPR with the 72-hour deadline.

It is important to make the distinction: The data protection module does not replace the full scope of the GDPR. It only checks whether the interface to the OEM is operated in accordance with data protection regulations. Existing GDPR compliance simplifies the proof considerably.

Anyone who has appointed an external data protection officer can present their reporting line and appointment certificate directly. CIVAC connects both worlds: The DSB module feeds the processing directory and TOM list, the ISB module collects the same data for the VDA-ISA-9 mapping.

The appointment certificate, signed, filed, verifiable. Anyone who appoints the external data protection officer via CIVAC documents both compliance lines in one system.

The deadline expires as soon as we become aware of it. 72 hours for reporting, three working days for supplier information to the OEM.

Supplier management: When Tier 2 becomes a risk

VDA ISA 6.0 requires a formalized supplier control process. A Tier 1 supplier must evaluate, contractually bind and regularly audit its own sub-tier suppliers. The OEM responsibility cascades down the supply chain.

Specifically required are: documented risk classification of suppliers, contractual information security clauses, self-disclosure or TISAX label check before ordering, as well as regular re-evaluation at least every three years.

IT service providers, cloud providers, engineering offices and shipping companies are critical. Anyone who does not monitor personnel changes or subcontractors risks finding findings in their own audit. The auditor draws samples from the supplier register.

A three-stage model is helpful: level A (critical, own TISAX label required), level B (medium, self-disclosure and contractual commitment), level C (non-critical, standard clauses). This classification must be justified and comprehensible.

CIVAC provides a supplier audit template in the workspace that is VDA-ISA compliant. The Supplier Auditor as a service complements the module if there is no internal capacity for supplier visits.

Licence the workspace for your internal representatives or have our representatives order it.

Preparation in 90 days: The operational roadmap

TISAX preparation in 90 days is ambitious, but feasible if an ISMS framework is in place. Day 1 to 14: Scoping workshop, location definition, data categories, determination of the assessment level and conclusion of contract with the audit provider.

Day 15 to 30: Gap analysis against VDA ISA 6.0, inclusion of all existing guidelines, identification of gaps in prototype protection and supplier control, creation of the action plan with those responsible and dates.

Day 31 to 60: Implementation of the prioritised measures. Typical quick wins are mobile device management, multi-factor authentication, clean desk policy, training wave for the workforce and updating the emergency manual.

Day 61 to 80: Internal audits, sample checks of maturity levels, correction of remaining gaps, creation of the audit folder with evidence for each VDA-ISA requirement. The auditor receives a complete dossier before the appointment.

Day 81 to 90: mock interview with key roles, test of the inspection route, escalation plan for major findings, final approval by management. The actual audit follows immediately afterwards.

CIVAC-SLA: The workspace is provided in two working days, instead of the classic two to six weeks for an ISMS consultant tender. The action plan starts on day three.

Costs, duration, repetition: What suppliers have to calculate

The total costs of an initial TISAX certification for medium-sized suppliers are typically between 35,000 and 120,000 euros. This range includes audit fees, external consulting, internal personnel expenses and technical investments.

The audit fees themselves range between 8,000 and 14,000 euros net per location for AL 2, and between 15,000 and 25,000 euros net for AL 3. In addition, there are travel costs for the auditors and follow-up work on findings.

External consulting costs between 25,000 and 60,000 euros, depending on the maturity of the original system. Anyone who uses CIVAC as a compliance platform and officer-as-a-service replaces part of this consulting service with a standardised, licensable solution.

The duration until the label is on average six to nine months from kickoff. Re-certifications every three years take considerably less time, typically two to three months, because the ISMS is already established.

Important: Major findings in the audit trigger a review procedure. The supplier must eliminate the deviation within nine months, otherwise the provisional audit status expires and the entire process restarts.

If you plan early, you save significantly. An established ISMS reduces initial certification costs by an estimated 30 to 50 percent.

From reading to labelling: This is how CIVAC supports you

CIVAC is a compliance platform and officer-as-a-service with two delivery models. Model one: You licence the workspace for your internal ISB role and use the 490 audit templates, the VDA-ISA to ISO 27001 mapping and the maturity trackers.

Model two: Licence the workspace for your internal representatives or have our representatives order them. In the second case, an external CIVAC ISB takes over the scoping session, the gap analysis, the action control and the audit support on site.

Both models use the same system: EU data residency, ISO/IEC 27001:2022 ISMS, defined reporting line to management, documented appointment certificate and an audit-proof audit folder. The auditor calls, the evidence is ready.

Typical entry-level situations: initial audit according to OEM requirements, repeat audit with gap closure, multi-location rollout, merging of ISO 27001-ISMS and TISAX-Scope, or crisis mode after major finding with a nine-month deadline.

Read more in CIVAC FAQ or arrange a 30-minute initial consultation. A senior ISB outlines the scope, effort and realistic schedule.

Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de.

FAQ

As Tier 2 suppliers, do we really need a TISAX label?

When your Tier 1 customer shares design or prototype data with you, the OEM requirement cascades. In practice, almost all German OEMs require a TISAX label at the second supplier level at the latest, and often lower. Self-disclosure is rarely enough.

How is TISAX different from ISO/IEC 27001:2022 certification?

ISO 27001 is a generic ISMS standard with 93 controls. TISAX uses the same logic, but adds automotive-specific topics such as prototype protection, data protection module and supplier control. Those who are ISO 27001 certified cover around 70 percent of the TISAX requirements.

What happens in the event of a major finding in the audit?

The auditor issues a provisional audit status. You have nine months to correct the deviation and carry out a review procedure. If the deadline is missed, the status expires and you start the entire process over again, including new audit fees.

Can we combine multiple locations under one label?

Only to a limited extent. Each physical location that processes data in scope requires its own assessment. For homogeneous locations, a sampling procedure can be applied for, which reduces the effort. The audit provider makes the decision based on scope and data categories.

How long does a TISAX audit specifically take?

An AL-2 audit typically involves two to three auditor days remotely. An AL-3 audit takes three to five days on site, depending on the site size and number of data categories. In addition, there is preparation of the audit folder and follow-up of the findings.

Will CIVAC assume the ISB role for TISAX preparation and ongoing operations?

Yes. CIVAC provides an external information security officer who takes over the appointment document, reporting line to management and operational control. Alternatively, licence the workspace for your internal ISB role. Both models use the same audit-proof system.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles