TISAX:VDA ISA 6 · Trusted information security assessment exchange

TISAXAutomotive infosec

The automotive industry's information security assessment based on VDA ISA — required by German OEMs before sharing prototypes, data and projects with suppliers.

SCHEME CARD · INFORMATION SECURITY
TISAXTrusted information security assessment exchange · VDA ISA 6
Who it's for
Automotive suppliers, engineering services and more
Audit model
Stage 1 + Stage 2 + surveillance
Certificate validity
3 years
Typical timeline
10–14 weeks
Listed in public registerCombines with ISO/IEC 27001
3 yrscertificate validity, with annual surveillance audits
2audit stages — documentation review, then on-site assessment
10–14weeks from application to certificate, typical timeline
1business day to a fixed offer after your application
Why companies certify

Who needs TISAX— and when

TISAX assessments verify information security, prototype protection and data protection at defined assessment levels. Results are shared through the ENX exchange platform, so one assessment serves all participating OEMs.

INDUSTRIES WE CERTIFY TO TISAX

Automotive suppliersEngineering servicesPrototype buildersAutomotive IT providersLogistics for OEMs
Not sure whether TISAX fits? Our auditors run a short diagnostic review and suggest the scheme — or a combination of two or three — that answers your customers' requirements.
Inside the standard

What the audit examines

01Information security

VDA ISA controls at AL2 or AL3.

02Prototype protection

Physical and organisational protection of prototypes.

03Data protection

GDPR-related requirements.

04Assessment levels

Scope and depth matched to OEM requirements.

05ENX exchange

Results shared with authorised partners.

What the audit covers

Requirements,clause by clause

TISAX is audited against these requirement areas. Open each one to see what auditors look for in your company.

Module ISInformation security+
Policies, asset management, access, cryptography, operations, incidents.
Module PPPrototype protection+
Physical security, handling of prototypes, test vehicles, events.
Module DPData protection+
Processing of personal data on behalf of the OEM.
ALAssessment levels+
AL1 self-assessment, AL2 plausibility check, AL3 on-site.
Benefits

What TISAXcertification gives you

  • Eligibility for OEM projects involving sensitive data
  • One assessment recognised by all participants
  • Structured security programme aligned to VDA ISA
  • Shorter supplier onboarding
  • Builds on ISO/IEC 27001 practices
Integrated audit

Hold more than one standard? One audit.

TISAX shares its structure with ISO/IEC 27001. We audit them together — one team, one visit, one report.

−25%audit days on average
1lead auditor for all standards
The path to certificate

Five steps from application to TISAX

Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.

STEP 1 / 5 · Application & offer
STEP 11 business day
Application & offer

You send a short application; a coordinator sizes the audit and sends a fixed offer.

→ Offer with audit plan
STEP 21–2 days
Stage 1 audit

Documentation review and readiness check — remote or on site. Gaps are listed, not penalised.

→ Readiness report
STEP 3By calculation
Stage 2 audit

On-site assessment of implementation and effectiveness with a team that knows your sector.

→ Audit report
STEP 45–10 days
Decision & certificate

Independent certification decision; the certificate is issued and entered into the public register.

→ TISAX certificate
STEP 5Annual
Surveillance & renewal

Annual surveillance keeps the certificate in force; re-certification in year three.

→ Certificate maintained
Readiness check

Are you readyfor Stage 1?

Tick what you already have. You do not need a perfect system to apply — you need a working one.

Your readiness
0%

Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.

Apply for TISAX →
FAQ · TISAX

Questions companiesask before certifying

Did not find yours? Call us — a coordinator answers within the same business day.

+38 (044) 332-30-76
How long is the certificate valid?+
Three years, maintained through annual surveillance audits and renewed by a re-certification audit in year three.
Can we combine it with other standards?+
Yes — integrated audits reduce total audit days and cost. Tell us which standards you hold and we size one combined audit.
How is the audit priced?+
Audit duration is calculated by international rules from headcount, sites and complexity, so quotations are comparable between certification bodies.
Related schemes

Often certifiedtogether

Get certifiedto TISAX

Send an application — we define scope and audit duration, and issue a fixed offer within one business day.

  • Auditors with experience in your industry
  • Fixed price — no surprises after Stage 1
  • Certificate listed in the public register
By sending the form you agree to the processing of the data for preparing a quotation.