Regulations

TISAX: AL1-AL3 Assessment Levels and the VDA ISA Catalogue

Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.

TL;DR

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment standard, operated by the ENX Association on the basis of the VDA ISA catalogue. It defines three assessment levels (AL1: self-assessment, AL2: remote document review, AL3: on-site audit) and optional labels (prototype protection, high data protection). A TISAX label is valid for three years and shareable through the ENX platform with customers who require it contractually.

What does TISAX cover for an automotive supplier?

As soon as an automotive customer requires access to sensitive information — development data, prototypes, project-related personal data — it typically requires a TISAX label at a given assessment level. The standard relies on the VDA ISA catalogue and is operated by the ENX Association, which accredits assessment providers and runs the platform used to exchange results between suppliers and customers.

Which assessment level, for which requirement?

TISAX assessment levels
LevelMethodScopeTypical use
AL1Self-assessment, no external verificationDeclarativeRarely sufficient for a demanding customer
AL2Remote document review by an accredited providerDocumentary evidence reviewStandard sensitive information
AL3Full on-site audit (interviews, technical checks)In-depth on-site verificationHighly sensitive information, prototypes, high data protection

CISAPP's multi-framework compliance module maps every VDA ISA control to evidence already collected for ISO 27001 or GDPR, avoiding repeated requests for the same information from internal teams or suppliers. Findings identified during a preparatory self-assessment are tracked in the evidence register through to closure, ahead of the official assessment by an accredited provider.

See also the ISO 27001 page.

FAQ

TISAX is an information security assessment exchange standard specific to the automotive industry. It relies on the VDA ISA control catalogue, published by the German automotive industry association (VDA), and is operated by the ENX Association, which accredits assessment providers and runs the platform used to share results.

Sources

  1. TISAX — official overview — ENX Association
  2. VDA ISA — assessment catalogue — VDA QMC

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account