In the automotive industry, technical data, designs, and prototype information have a value comparable to the product itself. Car manufacturers therefore expect their suppliers to demonstrate a documented level of information protection. TISAX is the standard that organizes this expected confidentiality and ensures consistency across the entire supply chain. Below, we explain from a practical perspective what this certification is, what requirements it places on partners, and why it is increasingly difficult to become an automotive supplier without it.
TISAX Certificate – What is it? Key Information
The TISAX® (Trusted Information Security Assessment Exchange) certificate is a mechanism evaluation and mutual exchange of information security audit results in the automotive industry. The standard was developed by the German automotive industry association VDA, and the system is managed ENX Association – an independent organization supervising the quality of assessments.
Before TISAX was established, each automotive company verified its suppliers according to its own surveys and procedures. This meant that companies working with multiple customers underwent several separate, overlapping audits. The VDA (Verband der Automobilindustrie) brought order to this chaos by creating a unified VDA-ISA requirements catalog – a common language used by the entire industry to describe and assess automotive information security. This foundation formed the basis for two complementary layers of the standard.
➤ We also recommend the article: Automotive Electroplating: 5 Amazing Applications
VDA-ISA Catalog – the foundation of security requirements
The VDA Information Security Assessment (ISA) is a catalog of information security requirements based on a recognized ISO/IEC 27001 standard, created and regularly updated by the VDA Information Security Committee. It defines the questions that the audited company answers. Effective April 1, 2024 ISA version 6.0, as announced by VDA – it extended the assessment to include a new area of "availability" in addition to the existing area of data confidentiality. The catalogue also provides a reference point for compliance with EU NIS 2 directive.
ENX Association – how does the TISAX results exchange work?
While the VDA is responsible for the content of the requirements, the ENX Association acts as the operator of the entire system: it approves audit providers, monitors their quality, and manages a platform for exchanging results between participants. The greatest benefit of this model is purely practical – the result of a single TISAX audit is valid for 3 years and recognized by all participants in the system. As a result, a single audit is sufficient for many clients simultaneously, eliminating the need to repeat the same assessment multiple times at the request of subsequent contractors.

TISAX requirements – what does the audit include?
The requirements are not a uniform list. The TISAX audit is divided into Assessment Levels, selected based on the sensitivity of the data being processed and the thematic areas being checked within the company. This division determines the depth of verification and the rigorous enforcement of OEM (original equipment manufacturer) requirements towards the supplier.
TISAX rating levels: AL1, AL2 and AL3
The system provides three levels of assessment, differing in form of verification and purpose:
| Level | Assessment form | Typical use |
| AL1 | Self-assessment | Low-sensitivity data, internal verification |
| AL2 | Remote/On-site audit by an independent, approved auditor | Standard required by most OEMs |
| AL3 | In-depth on-site audit, extended evidence verification | Particularly sensitive data (defense secrets, classified information) |
In the practice of automotive projects, the default threshold is AL2 – it provides the recipient with independent confirmation, not just a supplier declaration.
Assessment areas – what does the auditor check in practice?
The ISA Catalogue covers several thematic areas. The audit verifies, among other things:
- security of IT systems and networks (access control, malware protection),
- physical security of facilities and production zones,
- protection of personal data in accordance with applicable regulations,
- security management for own suppliers and subcontractors,
- business continuity and incident response,
- protection of prototypes and design data provided by the client.
This last point is crucial from the perspective of enforcing OEM requirements towards the supplier – it is around the protection of prototypes and design documentation that most of the expectations of manufacturers focus.
TISAX in the automotive supply chain – OEM, Tier 1 and Tier 2
TISAX doesn't operate in a vacuum – its strength comes from its consistent application throughout the supply chain. Vehicle manufacturers such as BMW Group, Mercedes-Benz, Volkswagen Group, and Stellantis require certification from their direct Tier 1 suppliers. They, in turn, contractually transfer this obligation to their own Tier 2 sub-suppliers, ensuring consistent information protection across every link. In this way, Tier 1 and Tier 2 certification creates a closed chain of trust.
The consequences of not having a current certificate are severe and measurable in business terms. A company without a valid TISAX result may be excluded from requests for proposals at the qualification stage, and in extreme cases, may lose ongoing collaboration. industrial cooperation for the automotive industry, the certificate is no longer a distinguishing feature, but has become a condition for entering the tender.
What does the path to TISAX certification look like step by step?
The path to achieving results TISAX audit follows a set sequence:
- Registration company on the ENX portal and obtaining a unique Participant-ID identifying the participant.
- Request for an assessment one of the approved audit providers – their current list is available on the ENX portal.
- Conducting an audit according to the ISA catalogue; for level AL2, verification with an auditor, including an on-site assessment, is mandatory.
- Publication of results on the TISAX Exchange portal – importantly, the results are not publicly available and only designated partners have access to them.
- Sharing Scope-ID or Assessment-ID to selected contractors, who can then verify the supplier's status.
It is worth planning the schedule realistically – from preparing the organization to closing the assessment, the entire cycle in larger plants can take several months, especially when the audit covers many locations and processes.

Strumet with TISAX certification – what does this mean for your project?
For an engineer or purchasing manager, a supplier's valid TISAX certificate translates into tangible, measurable benefits. Working with an audited partner eliminates the need to conduct your own, costly information security verification with that supplier. It also confirms that the supplier meets the information requirements set by OEMs, and actually shortens the qualification process in projects where TISAX is a necessary condition.
Strumet is TISAX certified. This is important wherever we are entrusted with project documentation or sensitive data – for example, in production certified airbag containers or dedicated pallets for car parts, where the shape and specification of the packaging result directly from the customer's design data.
If you are planning a project requiring a TISAX-compliant supplier, check out our range of industrial cooperation for automotive and contact our team – we will help you tailor the solution to your OEM’s requirements.
FAQ – most frequently asked questions about the TISAX® certificate
Is the TISAX certificate mandatory for all automotive suppliers?
Formally, this isn't a legal requirement, but a contractual one. In practice, however, most OEMs and Tier 1 suppliers condition their cooperation on a valid certificate, making it a de facto entry requirement for companies processing industry data.
Does a Tier 2 supplier also need to be TISAX certified?
Very often, yes. Tier 1 suppliers typically contractually transfer the certification requirement to their subcontractors to maintain a consistent level of information protection throughout the supply chain.
How long is the TISAX certificate valid and when does it need to be renewed?
The TISAX assessment result is valid for three years. To maintain continued status with contractors, it is advisable to initiate the re-audit process well in advance of this deadline.
How long does a TISAX audit take and what does it look like?
The audit itself typically takes from one to several days, depending on the scope and number of locations. The entire process—from organizational preparation, through assessment, to publication of results—can stretch over several months in larger companies.
What is the difference between TISAX and ISO 27001?
The ISA requirements catalog is based on the ISO/IEC 27001 standard but expands it to include specific automotive industry requirements, including prototype protection. The key difference is the mechanism for mutual recognition of results between participants, which the ISO standard itself does not provide.






