home / frameworks / tisax

// Industry frameworks and attestations

TISAX (Trusted Information Security Assessment Exchange)

TISAX is the automotive industry's system for assessing suppliers against the VDA ISA catalogue and sharing the results. Assessments by ENX-accredited audit providers produce TISAX labels that are valid for 3 years.

International (German automotive industry)

Overview

TISAX, the Trusted Information Security Assessment Exchange, is the automotive industry's shared system for assessing and exchanging information security results between companies. The ENX Association governs it, and the German Association of the Automotive Industry (VDA) publishes the VDA Information Security Assessment (VDA ISA) catalogue it uses. The catalogue covers information security, with added modules for prototype protection and data protection. Results are issued as TISAX labels. They're valid for 3 years and shared through the ENX portal only with the partners the company chooses.

Assessments are carried out by audit providers accredited by ENX, at assessment level 2, a plausibility check of the self-assessment through evidence and interviews, or level 3, a thorough on-site review, depending on the labels needed. Current assessments use VDA ISA 6, in effect since April 1, 2024. The VDA published ISA2027 on July 1, 2026, and it applies to assessments ordered from January 1, 2027, after which a new ISA version is to follow each summer and take effect the next January. Existing labels stay valid.

Canadian auto parts makers, engineering firms, tooling shops, and software suppliers meet TISAX when a German automaker or a large tier 1 supplier writes it into a purchase agreement, often before prototype parts or confidential drawings are shared. No Canadian regulator is involved, and the Standards Council of Canada has no role in it. ENX lists approved audit providers online. Since TISAX is an assessment exchange rather than an ISO certificate, a company that holds ISO 27001 still needs a TISAX assessment, although much of its evidence can be reused.

Who it applies to in Canada

Suppliers and service providers in the automotive value chain that handle confidential information, prototypes, or personal data for automakers and their larger suppliers.

Canadian auto parts makers, engineering firms, and software suppliers are asked for TISAX labels by German automakers and tier 1 suppliers before confidential data or prototype parts are shared.

Controls at a glance

The VDA ISA catalogue has an information security module organized in chapters, plus optional prototype protection and data protection modules.

Information security policies and organization

  • Security policy approved by management
  • Defined security organization and responsibilities
  • Asset inventory and classification
  • Information security risk management
  • Handling security events, incidents, and crises

Human resources

  • Screening and qualification of staff
  • Contractual confidentiality obligations
  • Security awareness training, including for managers
  • Rules for mobile and remote work

Physical security

  • Security zones with controlled access
  • Protection of facilities and equipment
  • Handling of mobile IT devices and data carriers

Identity and access management

  • Managing identification means such as badges and tokens
  • Secure authentication of users
  • Access rights based on need to know

IT security and cyber security

  • Cryptography and key management
  • Network security and segmentation
  • Malware protection, logging, and vulnerability management
  • Change management and secure development
  • Backup and recovery
  • Security of external IT and cloud services

Supplier relationships

  • Security requirements in supplier contracts
  • Checking supplier security, more closely for high protection needs
  • Non-disclosure agreements before sharing information

Compliance

  • Identifying legal, regulatory, and contractual requirements
  • Protecting personal data
  • Regular review of security compliance

Prototype protection module

  • Organizational requirements for prototype confidentiality
  • Physical and environmental security for prototype areas
  • Handling test vehicles, events, and photo shoots
  • Traceability and disposal of protected vehicles (added in ISA2027)

Data protection module

  • Processing personal data as a processor under the GDPR
  • Data protection organization and staff training
  • Extra safeguards for special categories of personal data

Certification and assessment

The company registers with ENX and defines its scope and assessment objectives, completes a self-assessment against the VDA ISA, and is assessed by an audit provider at level 2 or 3. Successful assessments produce TISAX labels, which the company shares with chosen partners through the ENX portal. TISAX labels are not ISO certificates.

Dates to know

2024-04-01
VDA ISA 6.0 takes effect, adding an availability label
2026-07-01
VDA publishes ISA2027
2026-10-01
German language ISA2027.1 released
2027-01-01
ISA2027 applies to newly ordered TISAX assessments

Resources

Official texts and free tools for TISAX. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. TISAX, ENX Association
  2. 10 Years of TISAX: VDA ISA2027 released, ENX Association
  3. TISAX Participant Handbook, ENX Association
  4. Information security, VDA