Compliance

TiSAX Certification: A Guide for Automotive Suppliers

If an OEM has asked for TiSAX, here's what it actually involves — the VDA ISA catalogue, assessment levels and labels, and how to prepare efficiently.

The Pelta Team8 min readUpdated Part of TiSAX

TiSAX — the Trusted Information Security Assessment Exchange — is how the automotive industry assesses and shares information security maturity. If an OEM or tier-one supplier has asked you for TiSAX, this guide explains what it involves and how to prepare without over-engineering it.

TiSAX is a mechanism, not a standard

The underlying requirements come from the VDA ISA (Information Security Assessment) catalogue, which draws heavily on ISO/IEC 27001. TiSAX is the mechanism that lets a supplier be assessed once by an accredited provider and then share the result with multiple partners through an exchange — avoiding a separate audit for every customer.

Assessment objectives and levels

You are assessed against specific objectives — for example handling of information with high protection needs, or prototype protection, or data protection — at an assessment level that reflects the sensitivity involved.

TiSAX assessment levels (indicative)
LevelApproachTypical use
AL 1Self-assessmentInternal use; not usually accepted for sharing
AL 2Evidence review, largely remote, plus a plausibility checkInformation with high protection needs
AL 3In-depth assessment including an on-site auditInformation with very high protection needs, prototypes
The TiSAX process

Register

On the ENX portal

Self-assess

Against VDA ISA

Remediate

Close gaps

Assess

Accredited provider

Labels

Shared via exchange

How to prepare efficiently

  • Start from the VDA ISA catalogue and do an honest self-assessment against your target objectives and level.
  • If you already hold ISO 27001, map those controls across first — the overlap is substantial.
  • Prioritise the areas the catalogue weights most heavily for your objectives, such as prototype protection if in scope.
  • Keep evidence linked to each control so the assessor can trace claims quickly.
Assessment levels, objectives and labels are defined by the current VDA ISA and TiSAX rules. Confirm the exact scope your customer requires before you begin.

Reuse, don't rebuild

Because TiSAX and ISO 27001 share so much, the worst outcome is running them as two separate programmes. Managing one control set with a single, connected evidence trail — and mapping it to both — is what keeps TiSAX from becoming a parallel workload. That shared-mapping model is how Pelta approaches overlapping information-security frameworks.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

ISO 27001

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding TiSAX

~75% carried over
Carried over from ISO 27001 New work for your team

Auto-completed from your existing program

Access controlRisk assessmentSupplier securityPhysical securityIncident responseSecure development

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

Frequently asked questions

What is TiSAX?+

TiSAX (Trusted Information Security Assessment Exchange) is the automotive industry's mechanism for assessing information security maturity against the VDA ISA catalogue and sharing the result with partners through an exchange.

Is TiSAX the same as ISO 27001?+

No, but they are closely related. The VDA ISA catalogue that TiSAX assesses against draws heavily on ISO 27001, so holding ISO 27001 gives you a substantial head start.

What are the TiSAX assessment levels?+

There are assessment levels reflecting the sensitivity of the information in scope, ranging from self-assessment through remote evidence review to an in-depth on-site audit. Your customer's requirements determine the level you need.

How long is a TiSAX label valid?+

TiSAX labels are valid for a defined period (commonly three years) before reassessment. Confirm the current validity and reassessment rules via the official TiSAX process.

Who needs TiSAX?+

Automotive suppliers and partners that exchange sensitive information with OEMs or tier-one suppliers, where the customer requires demonstrated information security maturity.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.