Sentrix

Framework · TISAX

TISAX: VDA ISA controls, ENX assessment, shared label

The automotive industry's information security standard: VDA ISA questionnaire, three assessment levels, ENX-accredited providers, label valid three years.

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment and exchange mechanism, administered by ENX Association on behalf of the VDA, the German automotive industry association. Many European OEMs require it from their suppliers; without a valid TISAX label, exchanging sensitive information with those customers is not possible.

Key facts

  • AL1 to AL3: three assessment levels, from self-assessment to full assessment.
  • 3 years: validity of a TISAX label.
  • IS, PP, DP: the VDA ISA questionnaire covers information security, prototype protection and data protection.
  • ENX: assessments are conducted by ENX-accredited audit providers and results are shared on the ENX portal.

What TISAX requires

TISAX assessments are based on the VDA ISA questionnaire. They are conducted by ENX-accredited audit providers and results are shared through the ENX portal rather than published publicly.

  1. Assessment Level 1 (AL1): self-assessment for basic information security requirements
  2. Assessment Level 2 (AL2): assessment with spot checks by an ENX-accredited provider
  3. Assessment Level 3 (AL3): full assessment for high-protection needs, such as prototype data
  4. Information security (IS): the VDA ISA controls, aligned substantially with ISO 27001
  5. Prototype protection (PP): separate requirements for suppliers handling vehicle prototype data or images
  6. Data protection (DP): requirements for suppliers processing personal data on behalf of OEMs

What Sentrix provides for TISAX

VDA ISA questionnaire preparation

Pre-populated VDA ISA questionnaire based on your actual control implementation. Evidence links attached to each question so your ENX assessor can verify directly.

Prototype protection (PP)

Separate control set tracked alongside your information security controls, with the physical security evidence specific to prototype data.

Assessment readiness tracking

Real-time readiness score against your selected assessment level (AL1, AL2, or AL3). Open findings prioritized by assessment impact, with owners assigned and tracked.

Label renewal management

Sentrix tracks your label expiry, maintains continuous evidence for renewal assessments, and alerts you six months before the deadline.

Crosswalks

  • ISO 27001: the VDA ISA aligns substantially with ISO 27001; Sentrix maps your ISO 27001 evidence to TISAX requirements and shows the gap.
  • NIS2: automotive suppliers established in the EU may also fall under NIS2; TISAX and ISO 27001 controls are mapped to the Article 21 measures.

Further reading

Third-party risk for the automotive supply chain.

See your TISAX readiness gap against the VDA ISA.

Contact us

Frequently asked questions

What is TISAX and who requires it?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment and exchange mechanism, administered by ENX Association. Many European OEMs require it from their tier-1 and tier-2 suppliers: without a valid TISAX label, exchanging sensitive information with those customers is not possible. Results are shared on the ENX portal rather than published.
What are the TISAX assessment levels?
Assessment Level 1 (AL1) is a self-assessment for basic requirements. Assessment Level 2 (AL2) is an assessment with spot checks by an ENX-accredited audit provider. Assessment Level 3 (AL3) is a full assessment for high-protection needs, such as prototype data. The VDA ISA questionnaire covers information security, prototype protection and data protection.
How long is a TISAX label valid?
A TISAX label is valid for three years. Sentrix tracks your label expiry, maintains continuous evidence for the renewal assessment and alerts you six months before the deadline, so renewal does not restart from a rebuilt program. Organizations already certified to ISO 27001 reuse their evidence, since the VDA ISA questionnaire aligns substantially with that standard.

Let's talk about your compliance program.

Last updated: 2026-09-17