TISAX – The Path to Certification.

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s standard for information security. mgm security partners brings your information security management system up to the VDA-ISA level, prepares you for the assessment, and supports you all the way to obtaining the shared label. Pragmatic, customized, and provided by experts who understand the technology—not just the questionnaire.
Candidates are typically ready for the assessment within a few months, depending on their starting point, the assessment objective, and the assessment level. Those who start early can achieve the required maturity level 3 without time pressure before the assessment date.
Background
What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s assessment and exchange process for information security. It is operated by the ENX Association on behalf of the VDA (German Association of the Automotive Industry). It is based on the VDA ISA (Information Security Assessment) questionnaire, which is closely modeled after ISO/IEC 27001 but supplements it with industry-specific requirements such as prototype protection and data protection. Since April 2024, version VDA ISA 6.0 has been the mandatory assessment standard.
Unlike with ISO 27001, companies do not receive a certificate, but rather one or more TISAX labels, which are shared with business partners via the ENX platform. This means that information security needs to be audited only once and can be demonstrated multiple times. For many suppliers and service providers, a TISAX label is now a prerequisite for working with manufacturers (OEMs). The assessment is conducted at three levels (AL 1 through AL 3) by accredited assessment service providers. A label is valid for three years.
The challenge
- The OEM is requiring a TISAX certification in the near term as a prerequisite for the contract
- It is unclear which test objective and which assessment level are actually required
- VDA ISA 6.0 includes over 300 requirements with a required maturity level of 3
- Prototype protection requires additional physical security measures
- Data protection audit objectives under Article 28 of the GDPR must be thoroughly addressed
- Uncertainty about whether the assessment by the testing service provider will be passed
Our Added Value
- Experienced auditors will guide you, seeing things from the auditor's perspective
- Experts who are familiar with the technology, not just the list of questions
- Pragmatic implementation tailored specifically to your company
- Clear Definition of Scope, Audit Objectives, and Assessment Level
- Integration with existing standards such as ISO 27001, where it is beneficial
- Reliable preparation and support all the way to obtaining the shared TISAX label
Our TISAX Services
Five coordinated steps, from the initial assessment to passing the evaluation and receiving the label.
1 - Scoping & Registration
Clarify the scope of the audit, define audit objectives and the assessment level, and prepare for ENX registration.
- Analyze the requirements of OEMs and partners
- Determine Appropriate Assessment Objectives (Labels) and Assessment Levels
- Clearly Define the Scope and Locations
- Assist with registration on the ENX platform
2 - Gap Analysis & Self-Assessment
Compare the current status against VDA ISA 6.0 and realistically assess the maturity level for each requirement.
- How to Complete the VDA ISA 6.0 Self-Assessment in a Structured Manner
- Assess the level of maturity for each requirement honestly and objectively
- Quantify the gaps to the required maturity level 3
- Prioritized Roadmap with Milestones Leading Up to the Assessment
3 - Measures & Maturity Level 3
: Structure processes, guidelines, and technology in such a way that they are actually put into practice rather than merely documented.
- Develop lean and audit-ready policies, processes, and documentation
- Define Roles, Responsibilities, and Reporting Lines
- Implementing Technical Controls in a Concrete and Effective Manner
- Ensure Level 3 maturity in practice rather than just on paper
4 - Prototyping & Data Protection
Cover industry-specific testing objectives that go beyond mere information security.
- Implementing and Evaluating Physical Security Measures for Prototype Protection
- Meet the requirements for test vehicles and test events
- Properly Set Up Data Processing in Accordance with Article 28 of the GDPR
- Take availability requirements into account as needed
5 - Assessment Support
: Get through the assessment with confidence at an accredited testing provider—AL 2 remotely or AL 3 on-site.
- Readiness Check and Preparation for the Assessment
- Support During the Assessment Process with the Testing Service Provider
- Handling Nonconformities and Corrective Actions
- Support for sharing the label via the ENX platform
From Registration to a Shared Label
We provide pragmatic, personalized support throughout the entire TISAX process—from scoping and self-assessment through implementation to the assessment and awarding of the label. The reassessment takes place after three years.
- 1 – Registration & Scoping: Register on the ENX platform; define the scope of the audit, audit objectives, and assessment level.
- 2 – Self-Assessment: Complete the VDA ISA 6.0 and evaluate the maturity level for each requirement.
- 3 – Actions & Maturity Level 3: Close gaps, establish processes, and achieve Maturity Level 3 in practice.
- 4 – TISAX Assessment: Audit conducted by an accredited service provider, AL 2 remotely or AL 3 on-site.
- 5 – Labels & Sharing: Receive labels and share them with partners via the ENX platform.

Which level and which labels you need
The appropriate assessment level and testing objectives depend on your protection needs and your partners’ requirements. A high protection need typically results in a remote assessment (AL 2), while a very high protection need or prototype protection requires an on-site assessment (AL 3). We determine both of these together with you to ensure that you have neither too much nor too little testing performed.

ISO 27001 as a Solid Foundation
An existing ISO 27001 ISMS already covers many TISAX requirements and significantly speeds up the path to obtaining the label. Risk management, policies, roles, and technical measures are already systematically established within the system, so that a large portion of the VDA-ISA catalog can build on existing processes. However, ISO 27001 is not mandatory for TISAX.
In the gap analysis, we assess what you already have in place, leverage existing structures where they are beneficial, and otherwise focus solely on implementing the additional requirements specified by TISAX, such as prototype protection and industry-specific data protection audit objectives.
No in-house resources? Outsourced ISB
The certification is the starting point, not the goal: The required level of maturity must be maintained on an ongoing basis; a reassessment is scheduled after three years. If you lack the internal capacity to do so, we can assume the role of Information Security Officer as a service and reliably maintain your ISMS at the TISAX level.
Auditors Who Understand the Technology
- 25+ Years of Enterprise Security Consulting
- Project experience with OEMs and suppliers
- A pragmatic, customized approach instead of a standard checklist
- 100% led by senior security experts
Our consultants are experienced auditors and security experts. They have an in-depth understanding of the VDA-ISA catalog and know how controls actually work from a technical perspective, based on over 25 years of experience working on projects for automakers, suppliers, industrial companies, and software manufacturers. We implement TISAX pragmatically and tailor it to each company’s specific needs, rather than rolling out standard templates. We do not conduct TISAX assessments, so we are fully on your side.
TISAX Consulting: Quick Answers to Your Questions
What is the difference between TISAX and ISO 27001?
TISAX is based on ISO/IEC 27001 but is an industry-specific standard for the automotive industry. It is based on the VDA ISA questionnaire, which covers not only information security but also prototype protection and data protection. Instead of a certificate, you receive TISAX labels, which are shared with partners via the ENX platform. An existing ISO 27001 ISMS provides an excellent foundation for TISAX.
What assessment level and labels do we need?
This depends on the security requirements for the information being processed and the specifications of your partners. High security requirements usually result in a remote assessment (AL 2), while very high security requirements and prototype protection typically result in an on-site assessment (AL 3). The OEM often specifies the test objectives and level. During the gap analysis, we work with you to determine what is actually necessary.
Does mgm also conduct the TISAX assessment?
No. The assessment may only be conducted by an audit service provider accredited by ENX. This is precisely why we can be fully on your side: We prepare your ISMS, conduct readiness checks, and guide you through the assessment without any conflict of interest.
How long does it take to get the label?
That depends on the current situation, the audit objective, and internal resources. Companies with an existing ISMS are often ready for assessment within a few months. The gap analysis quickly provides a reliable roadmap with realistic time and resource estimates and milestones leading up to the required maturity level 3.
How long is a TISAX label valid?
A TISAX certification is valid for three years. After that, a reassessment is required to renew the certification. The required maturity level must be maintained throughout the entire validity period. If you lack the internal capacity to do so, we—as your external information security officer—will reliably ensure that your ISMS remains up to standard.
