Skip to content

TISAX · Cybersecurity & Cloud

TISAX: VDA ISA, labels, and what automotive OEMs actually check in ENX

How automotive suppliers prepare for TISAX — assessment levels, prototype protection, and the ENX portal labels customers look up.

6 min read

TISAX is the automotive industry's assessment and exchange mechanism for information security, based on the VDA ISA and operated through the ENX ecosystem. OEMs and tier suppliers use it to verify labels rather than re-auditing every partner from scratch.

A TISAX project is not simply an ISO 27001 audit with automotive wording. Assessment objectives, sites, prototype protection, data classification, physical security, and the label your customer expects all shape the work.

The paired checklist helps teams prepare evidence and close gaps. This guide explains the judgment needed around scope, objectives, facilities, and customer expectations so the checklist does not become a generic security questionnaire.

What TISAX actually is

TISAX provides a standardized way for automotive companies to assess and share information-security results. The VDA ISA questionnaire covers information security and, depending on objectives, topics such as prototype protection and data protection. Assessment levels influence depth and method.

The result buyers care about is the appropriate label visible through ENX for the right participant, scope, and location. A supplier may have strong security controls and still fail a customer requirement if the wrong assessment objective was selected or the relevant engineering site was not included.

TISAX is also a customer-communication mechanism. The label tells an OEM or tier customer whether the supplier met the expected objective for the relevant scope, but it does not explain every internal control nuance. That makes early alignment on requested labels, locations, and deadlines as important as the assessment evidence itself. Suppliers should keep that alignment in the project file, because sales, quality, and security may otherwise optimize for different labels and discover the mismatch only when the customer checks ENX.

Decisions the checklist will not make for you

The checklist cannot choose the assessment objective. That decision should come from customer requirements, RFQ language, the data handled, prototype exposure, and the type of automotive work performed. Picking the cheapest or easiest objective can produce a label that does not satisfy the OEM.

It also cannot decide the site scope. Engineering offices, CAD environments, test facilities, plants, and remote teams may handle customer information differently. Leadership must decide which locations and processes belong in the assessment and document why.

The checklist will not translate every ISO control into TISAX evidence. ISO 27001 can help, but the assessment expects answers in the VDA ISA shape, including automotive-specific concerns such as prototype handling and physical protection.

Where teams actually fail

The first failure is assuming ISO certification grants TISAX readiness. ISO may provide a control foundation, but TISAX customers expect a valid ENX label with the right objective and scope. A certificate story is rarely enough when the RFQ specifically names TISAX.

The second failure is selecting the wrong assessment objective. Teams prepare for standard information security when the customer needs prototype protection, or they overlook data-protection expectations attached to the work. The mistake may not surface until procurement checks the label.

Forgotten locations are equally painful. A CAD site, small design studio, or outsourced engineering location may hold OEM drawings or prototype information but sit outside the assessed scope. Labels also expire, and teams miss renewals because ownership sits with sales rather than security or quality.

Physical and prototype controls are frequent weak spots because they sit outside classic IT ownership. Visitor handling, clean-desk behavior, camera restrictions, test-vehicle access, secure disposal, and segregated project areas may determine whether the automotive objective is credible. If facilities and engineering are absent from readiness, the IT team will miss material evidence.

How to use the paired checklist

Begin with the customer requirement. Capture the requested label, assessment objective, assessment level, participant, locations, and deadline. Then use the checklist to validate that your preparation matches the label the buyer will search for in ENX.

Run the checklist with information security, facilities, engineering, HR, quality, and the customer-program owner. TISAX readiness often fails at physical access, prototype handling, classification, supplier handling, or site evidence rather than at familiar IT policy controls.

After the assessment, keep the checklist as a label-maintenance tool. Track corrective actions, scope changes, new sites, customer data flows, and renewal dates so TISAX remains an operational capability rather than a one-time scramble. Review it whenever a new OEM program starts, because customer data handling can change before the next formal assessment cycle. Keep customer-request evidence with the label file so sales cannot accidentally promise the wrong objective to procurement.

What teams get wrong

ISO 27001 certification means the customer will accept us for TISAX.
ISO can support controls, but customers asking for TISAX usually expect the correct ENX label, objective, scope, and assessment level. Map ISO evidence where it helps, then prepare the VDA ISA and automotive-specific proof.
One assessed office covers every automotive project.
The scope must include the locations and processes that actually handle customer information, CAD, prototypes, or relevant services. A missed design office or supplier location can make the label commercially unusable.
The label is permanent once achieved.
Labels have validity periods and must be maintained through renewals, scope updates, and corrective-action tracking. Assign operational ownership so the label does not expire unnoticed between RFQs.

When the checklist is enough — and when it is not

  • Customer requirements do not clearly state the TISAX assessment objective or label needed.
  • Prototype, CAD, or customer confidential information is handled at sites outside the proposed scope.
  • An RFQ deadline depends on a label that is expired, wrong, or not yet visible in ENX.
  • ISO evidence is being reused without mapping to VDA ISA expectations.

Related checklists

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer