Win 1 year's access to Information Security E-Learning at our 50th Cyberzone(register)

What is TISAX?

TISAX is the benchmark for information security in the automotive sector. It guarantees compliance with OEM requirements. We support you every step of the way to achieve and maintain this high standard.

Contact an consultant
TISAX logo

What's the use of TISAX?

TISAX (Trusted Information Security Assessment Exchange) is a label developed specifically for the automotive industry, designed to guarantee optimum security management of shared information.

Created by the ENX association, it meets the high expectations of automakers, suppliers and partners in terms of confidentiality, integrity and availability of sensitive data. It is aligned with ISO 27001, while incorporating requirements specific to the automotive sector.

Why is TISAX essential?

In a sector where collaboration is key, TISAX guarantees mutual trust by certifying compliance with safety standards. This label establishes a unified standard for the automotive industry, replacing individual manufacturer assessments and simplifying exchanges in the supply chain.

Labeled companies benefit from easier access to tenders, fewer redundant audits and better risk management of sensitive data. TISAX protects prototype drawings, production data and confidential customer information.

Required by many OEMs, this certification is a competitive advantage that strengthens market position. It also helps prevent cyberthreats and ensures regulatory compliance.

Finally, the TISAX label promotes continuous improvement in safety practices, ensuring effective protection against specific industry challenges, such as securing connected vehicles and protecting design data.

85% of partners require TISAX for automotive collaboration
For more content, visit our YouTube page

Key points of TISAX

The TISAX label aims to standardize information security assessments in the automotive industry. It enables companies to securely share their assessment results with other TISAX participants via the ENX platform.

Here are the perimeters of the TISAX label:

1 ) Information security

This perimeter is mandatory to obtain the TISAX label, and is defined to encompass all critical aspects of information security, mainly based on ISO 27001 and its Annex A. Here are the key chapters of this perimeter:  

  1. Information security policies and organization: Implementation of rules and procedures to protect the organization's sensitive information, and appointment of security officers.
  2. Human Resources information security: Protection of employees' personal data, such as hiring, payroll and performance evaluation information.
  3. Physical security and business continuity: Securing the organization's premises, equipment and physical assets, as well as implementing business continuity plans in the event of an incident.
  4. Identity and access management: controlling access to the organization's information and systems, assigning appropriate access rights to each user.
  5. IT security and cybersecurity: protecting IT systems and networks against cyberthreats, such as viruses, attacks and hacking attempts.
  6. Supplier relations: information security related to relations with the organization's suppliers and partners, ensuring that they also meet high security standards.
  7. Compliance with requirements: Compliance with safety requirements set by partners or applicable regulations, including documentation and preparation for compliance audits.
2) Prototype management

The prototype management process applies to companies that manufacture, store or use customer-supplied components, parts or vehicles classified as requiring protection.

The assessment includes requirements for physical safety and safety in the surrounding area, as well as specific organizational requirements for handling prototypes.

For companies carrying out road tests and trials with customer-supplied vehicles, specific requirements for the treatment of prototypes during road tests are also included.

After successful evaluation, companies automatically receive the TISAX "Protection of prototype parts and components" label.

Requirements relating to physical safety and safety in the surrounding area are not necessarily included in the assessment, but if sites are equipped accordingly, the assessment objective "Protection of prototype vehicles" can also be selected.

Some companies may have additional specific requirements for handling prototypes during presentations, events, films and photo shoots in protected rooms and in public, which are also part of the assessment.

3) Data protection: Requirements for processing personal data

If you process personal data as a processor in accordance with Article 28 of the GDPR, you will probably need to select " Data protection ".

If you process special categories of personal data (such as health data or data on religious beliefs) as a processor in accordance withArticle 28 of the GDPR, you will probably need to select " Data protection for special categories of personal data ".

TISAX evaluation levels

TISAX distinguishes three "assessment levels" (AL).

A higher rating level means greater rating intensity. They reflect one of three different levels of protection: Level 1 (normal), Level 2 (high) and Level 3 (very high).

Level 1 (AL1)

Assessments at this level are primarily intended for internal purposes. The VDA assessment checklist must be completed by the company. They have a low level of confidence and require self-assessment (auditor checks that it exists, but no more).

Level 2 (AL2)

The auditor asks for proof of the self-assessment (audit), conducting interviews with the customer to verify compliance with the TISAX (VDA) standard.

Level 3 (AL3)

Requires more in-depth verification with on-site inspection and face-to-face interviews.

For further details on the standard, our experts are at your disposal.

Contact an consultant

Certification

The TISAX certification process is based on several structured steps to ensure your organization's compliance with information security requirements. Here is a summary of the main phases:

1. Official opening meeting

2. Initial assessment

3. Closing meeting

4. TISAX evaluation report

5. Corrective action plan

6. Provisional TISAX labels (if applicable)

7. Follow-up assessment

Note that the follow-up assessment must be carried out within 9 months of the initial assessment.

Tips from FeelAgile

Obtaining TISAX certification requires careful preparation. To achieve it, you need to structure your approach and avoid common mistakes. Here are 4 key tips for success.

Expert support can also make all the difference. It saves time, helps youavoid mistakes and prepares you effectively for the assessment.

Raising employee awareness

Involving and training employees in information security ensures that best practices are applied effectively.

Defining the scope

Identify precisely the sites, processes and systems concerned to avoid any ambiguity during the assessment.

Use the right tool

A compliance management solution (such as Oversecur) makes it easy to monitor security measures and evaluate deviations.

Continuous improvement approach

Implement regular actions to enhance safety and meet TISAX requirements over the long term.

The benefits

In the automotive industry, TISAX has become an essential standard for securing exchanges and reinforcing trust between partners.  

‍TISAXis a competitive lever that enhances security, simplifies audits and opens up new business opportunities.

Recognition and trust

TISAX certification means that we are officially recognized as a secure supplier, meeting the requirements of automakers and equipment manufacturers. This label strengthens the confidence of our partners and enhances our image of reliability with our customers.

Business opportunities

Certification facilitates access to calls for tender and enables companies to position themselves as preferred partners. It also opens up opportunities in new markets, particularly abroad, by guaranteeing a recognized level of safety.

Safety and risk management

TISAX improves the security posture by imposing strict practices for the protection of sensitive data. By reducing vulnerabilities, it limits the risk of data breaches and strengthens resilience in the face of cyber threats.

FAQ

Frequently asked questions

All you need to know about TISAX

Who is TISAX for?

Several evaluation levels for TISAX certification: which one to choose?

How do I choose my certification scope?

What does ENX do?

Our experts will get back to you within 24 hours.

Do you have any questions? Would you like a quote for certification or support?

+ More than 180 companies place their trust in us
jamespot logo
auqfood logo
SBS Interactive logo
Logo seqino
Logo aniah
Logo airon telematica