Framework · TISAX
TISAX: VDA ISA controls, ENX assessment, shared label
The automotive industry's information security standard: VDA ISA questionnaire, three assessment levels, ENX-accredited providers, label valid three years.
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment and exchange mechanism, administered by ENX Association on behalf of the VDA, the German automotive industry association. Many European OEMs require it from their suppliers; without a valid TISAX label, exchanging sensitive information with those customers is not possible.
Key facts
- AL1 to AL3: three assessment levels, from self-assessment to full assessment.
- 3 years: validity of a TISAX label.
- IS, PP, DP: the VDA ISA questionnaire covers information security, prototype protection and data protection.
- ENX: assessments are conducted by ENX-accredited audit providers and results are shared on the ENX portal.
What TISAX requires
TISAX assessments are based on the VDA ISA questionnaire. They are conducted by ENX-accredited audit providers and results are shared through the ENX portal rather than published publicly.
- Assessment Level 1 (AL1): self-assessment for basic information security requirements
- Assessment Level 2 (AL2): assessment with spot checks by an ENX-accredited provider
- Assessment Level 3 (AL3): full assessment for high-protection needs, such as prototype data
- Information security (IS): the VDA ISA controls, aligned substantially with ISO 27001
- Prototype protection (PP): separate requirements for suppliers handling vehicle prototype data or images
- Data protection (DP): requirements for suppliers processing personal data on behalf of OEMs
What Sentrix provides for TISAX
VDA ISA questionnaire preparation
Pre-populated VDA ISA questionnaire based on your actual control implementation. Evidence links attached to each question so your ENX assessor can verify directly.
Prototype protection (PP)
Separate control set tracked alongside your information security controls, with the physical security evidence specific to prototype data.
Assessment readiness tracking
Real-time readiness score against your selected assessment level (AL1, AL2, or AL3). Open findings prioritized by assessment impact, with owners assigned and tracked.
Label renewal management
Sentrix tracks your label expiry, maintains continuous evidence for renewal assessments, and alerts you six months before the deadline.
Crosswalks
- ISO 27001: the VDA ISA aligns substantially with ISO 27001; Sentrix maps your ISO 27001 evidence to TISAX requirements and shows the gap.
- NIS2: automotive suppliers established in the EU may also fall under NIS2; TISAX and ISO 27001 controls are mapped to the Article 21 measures.
Further reading
Third-party risk for the automotive supply chain.
See your TISAX readiness gap against the VDA ISA.
Frequently asked questions
- What is TISAX and who requires it?
- TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment and exchange mechanism, administered by ENX Association. Many European OEMs require it from their tier-1 and tier-2 suppliers: without a valid TISAX label, exchanging sensitive information with those customers is not possible. Results are shared on the ENX portal rather than published.
- What are the TISAX assessment levels?
- Assessment Level 1 (AL1) is a self-assessment for basic requirements. Assessment Level 2 (AL2) is an assessment with spot checks by an ENX-accredited audit provider. Assessment Level 3 (AL3) is a full assessment for high-protection needs, such as prototype data. The VDA ISA questionnaire covers information security, prototype protection and data protection.
- How long is a TISAX label valid?
- A TISAX label is valid for three years. Sentrix tracks your label expiry, maintains continuous evidence for the renewal assessment and alerts you six months before the deadline, so renewal does not restart from a rebuilt program. Organizations already certified to ISO 27001 reuse their evidence, since the VDA ISA questionnaire aligns substantially with that standard.
Related pages
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · NIS2
NIS2: ten measures, management liability, 24-hour warning
The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.
Let's talk about your compliance program.
Last updated: 2026-09-17
