Attestation · Last verified

ENX Vehicle Cyber Security

ENX VCS is ENX Association's ISO/SAE 21434-based third-party audit scheme for a supplier's Vehicle Cybersecurity Management System, issuing a label. Audit results form the basis of an ENX VCS Label, valid TISAX labels are a precondition for locations in scope, and the scheme fully implements ISO/PAS 5112's recommendations.

Class
Attestation
Owner
ENX Association
Public register
Not confirmed at our last check
Last verified

What it is

ENX describes the scheme in its own words: "ENX VCS is a harmonized ISO/SAE 21434 based scheme for the independent third party audit of the Vehicle Cybersecurity Management System (V-CSMS) of cybersecurity relevant automotive suppliers." It is "Based on ISO/SAE 21434 and fully implementing the recommendations of ISO/PAS 5112", and "Audit results form the basis for the issuance of an ENX VCS Label".

The scheme layers on top of TISAX rather than beside it — the FAQ states: "The participant should have valid TISAX labels for all locations in the VCS audit scope at the time of performing the audit."

The scheme is in its introduction phase. The FAQ states: "During the ongoing introduction phase, registration for ENX VCS is free of charge." What follows the introduction phase was not stated on the pages opened on 31 August 2026.

ENX also connects the scheme to vehicle type approval context on its own page: "UNECE Regulation No. 155 requires vehicle manufacturers to demonstrate the effectiveness of their Cybersecurity Management System (CSMS), including through organizational audits" — that obligation sits with vehicle manufacturers; ENX VCS is the supply-chain audit scheme built alongside it.

Who owns it

ENX VCS is run by ENX Association, in its own words "a non-profit organisation founded by a group of automotive manufacturers, national automotive associations, and automotive suppliers".

Who assesses it

Audits are performed by independent third parties; ENX states its own role as: "ENX provides centralized scheme governance through: Admission and oversight of ENX VCS audit providers". The public list of admitted VCS audit providers could not be opened as of 31 August 2026 (login wall).

Who asks for it

Voluntary. The scheme owner's own FAQ states: "Similar to TISAX, ENX VCS audit is not mandatory." ENX adds an expectation, not an obligation: "in due course of time, we expect it to become a best practice". No OEM-imposed supplier obligation was identified on enx.com or the ENX VCS FAQ as of 31 August 2026 — confirm against ENX (vcs@enx.com).

The scheme owner's own FAQ places the audit outside any obligation, on the same footing as TISAX (see the demand note above). The only OEM sentence on the FAQ describes relief, not requirement: "It aims to relieve OEMs from the need to create and maintain a list of acceptable assurances." No OEM-imposed supplier obligation was identified on enx.com or the ENX VCS FAQ as of 31 August 2026 — confirm against ENX (vcs@enx.com).

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"ENX Vehicle Cyber Security." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/enx-vcs

All frameworks & audits →