FRAMEWORK GUIDE
TISAX: a Tier-2/3 supplier response guide
TISAX (Trusted Information Security Assessment Exchange) is a shared automotive-industry mechanism, operated by the ENX Association, for assessing and exchanging information-security results based on the VDA ISA criteria developed by the German automotive industry association (VDA). It was created to cut down on repeated one-off security audits as OEMs and Tier-1s exchange engineering data, prototypes, and personal data with suppliers. Participants go through an audit by a certified provider, receive a label, and choose which partners they share the results with.
Who asks for it — and why
OEMs and Tier-1 buyers increasingly ask for a TISAX label, or an equivalent proof of information-security maturity, before granting access to design data, prototypes, or supply-chain systems. Requirements tend to be stricter for suppliers involved in new-vehicle development programs or connected to a customer's IT systems. ESG self-assessments also use information-security governance as a reference signal.
Key requirement areas
- Information security policy and organization
Naming a responsible owner, documenting policy, and establishing a risk-assessment process are the baseline requirements.
- Access control and technical security
System and data access management, encryption, and network security are assessed as technical controls.
- Prototype and physical security
Automotive-specific requirements cover preventing prototype leaks, controlling photography, and managing physical access.
What Tier-2/3 suppliers should do
For Tier-2/3 suppliers, the practical points are: (1) confirm which assessment level (AL1-AL3) and scope the customer actually needs, (2) even before pursuing a label, document baseline controls such as access management, confidentiality, and incident response, and (3) widen the scope to include physical security for prototypes and drawings. The information-security items in this assessment can help you check your current readiness.
4 questions in our free self-assessment are grounded in this framework.
Example questions
- Does your company hold a recognized information-security management certification or independent assessment?
- Which data-protection and privacy measures has your company implemented?
- Does your company maintain a documented procedure to detect, respond to and notify data breaches and information-security incidents?
- How does your company protect confidential technical information — customer drawings and specifications, your own trade secrets, and prototype or sample parts?
FAQ
- Can I still work on automotive projects without a TISAX label?
- Whether it's mandatory depends on the customer and the project. Still, requests are increasingly common whenever design data or personal data is involved, so having baseline controls in place ahead of time makes responding much easier.
- How is TISAX different from ISO 27001?
- TISAX combines an automotive-specific assessment framework (VDA ISA) with an industry-wide results-sharing platform, while ISO 27001 is a general-purpose international standard for information security management systems. The two are often cross-referenced but remain separate certifications.
Public sources
Informational only — this does not replace an official ESG evaluation. Independent content; not affiliated with or endorsed by any framework organization.