Regulations
TISAX: AL1-AL3 Assessment Levels and the VDA ISA Catalogue
Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.
TL;DR
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment standard, operated by the ENX Association on the basis of the VDA ISA catalogue. It defines three assessment levels (AL1: self-assessment, AL2: remote document review, AL3: on-site audit) and optional labels (prototype protection, high data protection). A TISAX label is valid for three years and shareable through the ENX platform with customers who require it contractually.
What does TISAX cover for an automotive supplier?
As soon as an automotive customer requires access to sensitive information — development data, prototypes, project-related personal data — it typically requires a TISAX label at a given assessment level. The standard relies on the VDA ISA catalogue and is operated by the ENX Association, which accredits assessment providers and runs the platform used to exchange results between suppliers and customers.
Which assessment level, for which requirement?
| Level | Method | Scope | Typical use |
|---|---|---|---|
| AL1 | Self-assessment, no external verification | Declarative | Rarely sufficient for a demanding customer |
| AL2 | Remote document review by an accredited provider | Documentary evidence review | Standard sensitive information |
| AL3 | Full on-site audit (interviews, technical checks) | In-depth on-site verification | Highly sensitive information, prototypes, high data protection |
How CISAPP links TISAX to your existing compliance
CISAPP's multi-framework compliance module maps every VDA ISA control to evidence already collected for ISO 27001 or GDPR, avoiding repeated requests for the same information from internal teams or suppliers. Findings identified during a preparatory self-assessment are tracked in the evidence register through to closure, ahead of the official assessment by an accredited provider.
See also the ISO 27001 page.
FAQ
TISAX is an information security assessment exchange standard specific to the automotive industry. It relies on the VDA ISA control catalogue, published by the German automotive industry association (VDA), and is operated by the ENX Association, which accredits assessment providers and runs the platform used to share results.
Sources
- TISAX — official overview — ENX Association
- VDA ISA — assessment catalogue — VDA QMC
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours